High severity8.8NVD Advisory· Published Oct 26, 2023· Updated Jun 17, 2026
CVE-2023-0897
CVE-2023-0897
Description
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:sielco:polyeco1000_firmware:1.9.3:*:*:*:cpu:*:*:*+ 3 more
- cpe:2.3:o:sielco:polyeco1000_firmware:1.9.3:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:1.9.4:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:10.19:*:*:*:fpga:*:*:*
- cpe:2.3:o:sielco:polyeco1000_firmware:2.0.6:*:*:*:cpu:*:*:*
cpe:2.3:o:sielco:polyeco300_firmware:10.19:*:*:*:fpga:*:*:*+ 2 more
- cpe:2.3:o:sielco:polyeco300_firmware:10.19:*:*:*:fpga:*:*:*
- cpe:2.3:o:sielco:polyeco300_firmware:2.0.0:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco300_firmware:2.0.2:*:*:*:cpu:*:*:*
cpe:2.3:o:sielco:polyeco500_firmware:1.7.0:*:*:*:cpu:*:*:*+ 1 more
- cpe:2.3:o:sielco:polyeco500_firmware:1.7.0:*:*:*:cpu:*:*:*
- cpe:2.3:o:sielco:polyeco500_firmware:10.16:*:*:*:fpga:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: CPU:2.0.6 FPGA:10.19
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-23-299-07nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.