Authorization bypass through user-controlled key in ETL3100 - CVE-2023-6929
Published: December 20, 2023
ETL3100
Eurotel
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insecure direct object references when the application provides direct access to objects based on user-supplied input. A remote attacker can bypass authorization, access the hidden resources on the system and execute privileged functionalities.