CVE-2023-46661
CVE-2023-46661 is a critical-severity vulnerability in Sielco Polyeco500 Firmware with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (43rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Sielco Polyeco500 Firmware
- Published:
- Last modified:
Description
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
Frequently asked questions
- What is CVE-2023-46661?
- Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
- How severe is CVE-2023-46661?
- CVE-2023-46661 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-46661 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (43rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-46661?
- CVE-2023-46661 primarily affects Sielco Polyeco500 Firmware. In total, 9 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-46661?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2023-46661 published?
- CVE-2023-46661 was published on 2023-10-26 and last updated on 2026-06-17.
References
Affected products (9)
- cpe:2.3:o:sielco:polyeco500_firmware:1.7.0:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco500_firmware:10.16:*:*:*:fpga:*:*:*
- cpe:2.3:o:sielco:polyeco300_firmware:2.0.0:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco300_firmware:2.0.2:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco300_firmware:10.19:*:*:*:fpga:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:1.9.3:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:1.9.4:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:2.0.6:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:10.19:*:*:*:fpga:*:*:*
More vulnerabilities in Sielco Polyeco500 Firmware
- CVE-2023-46665 — Critical (CVSS 9.8): Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a…
- CVE-2023-5754 — Critical (CVSS 9.1): Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password…
- CVE-2023-0897 — High (CVSS 8.8): Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force…
- CVE-2023-46664 — High (CVSS 7.5): Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct…
- CVE-2023-46663 — High (CVSS 7.5): Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages.…
- CVE-2023-46662 — High (CVSS 7.5): Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement.…
All CVEs affecting Sielco Polyeco500 Firmware →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →