PT-2023-13020 · Landis+Gyr · Landis+Gyr E850
Aarón Flecha Menéndez
+2
·
Published
2023-02-01
·
Updated
2023-02-10
·
CVE-2022-3083
CVSS v3.1
3.9
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Landis+Gyr E850 (ZMQ200) versions all
Description
The device's web application navigation depends on the value of the
session cookie. If an attacker changes the session cookie values, the web application could become inaccessible for the user. This issue is related to the reliance on cookies without validation and integrity.Recommendations
For all versions, consider implementing cookie validation and integrity checks to prevent unauthorized modifications. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Landis+Gyr E850