PT-2022-24686 · Unknown · Smart Evision

Gary Tan

+1

·

Published

2022-09-28

·

Updated

2022-09-28

·

CVE-2022-39031

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smart eVision (affected versions not specified)
Description The issue is related to insufficient authorization for the task acquisition function. An unauthorized remote attacker can exploit this to acquire the Session IDs of other general users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-39031

Affected Products

Smart Evision