ZeroHour

CVE-2022-3083

CVSS 3.1
5.4 medium
EPSS
<1%p28
Published
()
Modified
Description

All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.

Vendors
landisgyr
Products
e850 firmware
Weakness
CWE-784, CWE-565
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.