PT-2023-13020 · Landis+Gyr · Landis+Gyr E850

·

CVE-2022-3083

·

Publicado

2023-02-01

·

Atualizado

2023-02-10

CVSS v3.1

3.9

Baixa

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Landis+Gyr E850 (ZMQ200) versions all
Description The device's web application navigation depends on the value of the session cookie. If an attacker changes the session cookie values, the web application could become inaccessible for the user. This issue is related to the reliance on cookies without validation and integrity.
Recommendations For all versions, consider implementing cookie validation and integrity checks to prevent unauthorized modifications. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-3083

Produtos afetados

Landis+Gyr E850