Security Advisory

CVE-2023-28398

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-28 20:08:09
Last updated 2025-01-16 21:37:57
Assigner icscert
State PUBLISHED

Description

Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully exploits this vulnerability could gain access to the pump controller and cause disruption in operation, modify data, or shut down the controller.