CVE-2021-25910

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/01/2021
Last modified:
05/02/2021

Description

Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zivautomation:4cct-ea6-334126bf_firmware:3.23.77.8.33251:*:*:*:*:*:*:*
cpe:2.3:h:zivautomation:4cct-ea6-334126bf:-:*:*:*:*:*:*:*