What the vulnerability does
01Description
Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.
Explanation of Vulnerability in Simple Terms
SedLex Traffic Manager versions up to 1.4.5 lack proper authorization checks, allowing authenticated users to modify or disable traffic management settings they should not have access to. An attacker with low-level credentials can alter integrity of the system's traffic control configuration. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Modify or disable traffic management settings without proper authorization.
Potential impact on your site
Unauthorized users can alter traffic control rules, potentially disrupting service availability or redirecting traffic.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges.
Key dates
External resources
Related vulnerabilities