7.5
CVSSv3

CVE-2023-28395

Published: 28/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an malicious user to hijack a session by predicting the session id and gain unauthorized access to the product.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

propumpservice osprey_pump_controller_firmware 1.01