PT-2023-13020 · Landis+Gyr · Landis+Gyr E850

·

CVE-2022-3083

·

Published

2023-02-01

·

Updated

2023-02-10

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Landis+Gyr E850 (ZMQ200) versions all
Description The device's web application navigation depends on the value of the session cookie. If an attacker changes the session cookie values, the web application could become inaccessible for the user. This issue is related to the reliance on cookies without validation and integrity.
Recommendations For all versions, consider implementing cookie validation and integrity checks to prevent unauthorized modifications. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3083

Affected Products

Landis+Gyr E850