PT-2023-18209 · Runestone · Runestone

Hsia.Angsh

·

Publicado

2023-02-09

·

Atualizado

2023-02-21

·

CVE-2023-21442

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Runestone versions prior to 2.9.09.003 Runestone versions prior to 3.2.01.007
Description The issue is related to improper access control in the Runestone application, allowing local attackers to obtain device location information.
Recommendations For versions prior to 2.9.09.003, update to version 2.9.09.003 or later to resolve the issue. For versions prior to 3.2.01.007, update to version 3.2.01.007 or later to resolve the issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-21442

Produtos afetados

Runestone