PT-2023-13020 · Landis+Gyr · Landis+Gyr E850

Aarón Flecha Menéndez

+2

·

Published

2023-02-01

·

Updated

2023-02-10

·

CVE-2022-3083

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Landis+Gyr E850 (ZMQ200) versions all
Description The device's web application navigation depends on the value of the session cookie. If an attacker changes the session cookie values, the web application could become inaccessible for the user. This issue is related to the reliance on cookies without validation and integrity.
Recommendations For all versions, consider implementing cookie validation and integrity checks to prevent unauthorized modifications. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-3083

Affected Products

Landis+Gyr E850