CVE-2023-37833
LOWCVSS 2.7/10EPSS 0.41%
Last modified
CVE-2023-37833 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elenos | Etg150 Firmware | 3.12 |
References
- https://github.com/strik3r0x1/Vulns/blob/main/BAC%20leads%20to%20access%20Traps%20configurations.mdExploit, Product, Third Party Advisory
- https://github.com/strik3r0x1/Vulns/blob/main/BAC%20leads%20to%20access%20Traps%20configurations.mdExploit, Product, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37833?
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.
How severe is CVE-2023-37833?
CVE-2023-37833 has a CVSS score of 2.7/10 (LOW severity). The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2023-37833?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37828A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-37829A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-3783A vulnerability was found in Webile 1.0.1. It has been class…5.4
- CVE-2023-37830A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-37831An issue discovered in Elenos ETG150 FM transmitter v3.12 al…5.3
- CVE-2023-37832A lack of rate limiting in Elenos ETG150 FM transmitter v3.1…7.5
- CVE-2023-37835Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE…
- CVE-2023-37836libjpeg commit db33a6e was discovered to contain a reachable…6.5
- CVE-2023-37837libjpeg commit db33a6e was discovered to contain a heap buff…6.5
- CVE-2023-37839An arbitrary file upload vulnerability in /dede/file_manage_…9.8
- CVE-2023-3784A vulnerability was found in Dooblou WiFi File Explorer 1.13…5.4
- CVE-2023-37847novel-plus v3.6.2 was discovered to contain a SQL injection …9.8
Are you affected by CVE-2023-37833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
