Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30801 | Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints. |
Fixes
Solution
Elcomplus has released an update to fix these vulnerabilities and recommends users upgrade to Version 2.3.4 or later. For more information, please contact Elcomplus support.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-04 |
|
History
Wed, 16 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T17:54:55.849Z
Reserved: 2021-11-16T00:00:00.000Z
Link: CVE-2021-43939
Updated: 2024-08-04T04:10:17.163Z
Status : Modified
Published: 2022-04-28T15:15:09.567
Modified: 2024-11-21T06:30:02.573
Link: CVE-2021-43939
No data.
OpenCVE Enrichment
No data.
EUVD