PT-2021-23382 · Maharashtra State Electricity Board · Mahavitara Android Application

Tejas Nitin Pingulkar

·

Published

2021-12-07

·

Updated

2021-12-08

·

CVE-2021-41716

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Maharashtra State Electricity Board Mahavitara Android Application versions 8.20 and prior
Description The issue allows for remote account takeover due to an OTP fixation vulnerability in the password reset function.
Recommendations For versions 8.20 and prior, update to a version that fixes the OTP fixation vulnerability in the password reset function to prevent remote account takeover.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41716

Affected Products

Mahavitara Android Application