ZeroHour

CVE-2023-36483

CVSS 3.1
6.5 medium
EPSS
<1%p41
Published
()
Modified
Description

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.

Vendors
honeywell
Products
masmobile asp.net services, masmobile classic
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.