PT-2023-13020 · Landis+Gyr · Landis+Gyr E850

Aarón Flecha Menéndez

+2

·

Publicado

2023-02-01

·

Atualizado

2023-02-10

·

CVE-2022-3083

CVSS v3.1

3.9

Baixa

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Landis+Gyr E850 (ZMQ200) versions all
Description The device's web application navigation depends on the value of the session cookie. If an attacker changes the session cookie values, the web application could become inaccessible for the user. This issue is related to the reliance on cookies without validation and integrity.
Recommendations For all versions, consider implementing cookie validation and integrity checks to prevent unauthorized modifications. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-3083

Produtos afetados

Landis+Gyr E850