Walchem Intuition Missing Authentication for Critical Function
Published Aug 23, 2023
7.5
HIGHCVSS 3.1
EPSS 0.63%
Description
Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could allow an attacker to download and export sensitive data.
Affected products
-
Affected
- ≥ 0, < 4.21
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Walchem | Intuition 9 | unaffected | Affected
|
- < 4.21
Running on/with
- n/a
-
Affected
- ≥ 0, < 4.21
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Walchem | Intuition 9 | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Walchem recommends upgrading all Intuition 9 firmware versions to v4.21 or later. The upgrade can be downloaded from the Walchem website https://www.walchem.com/ . https://www.walchem.com/
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42239 Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-229-04 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42239 | Advisory | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-229-04 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data