PT-2024-16234 · Unknown · Matrix Door Controller Cosec Vega Faxq

Arko Dhar

+1

·

Published

2024-10-25

·

Updated

2024-11-14

·

CVE-2024-10381

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matrix Door Controller Cosec Vega FAXQ (affected versions not specified)
Description The issue arises from improper implementation of session management at the web-based management interface. A remote attacker could exploit this by sending a specially crafted HTTP request to the vulnerable device. Successful exploitation could allow a remote attacker to gain unauthorized access and take complete control of the targeted device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-10381

Affected Products

Matrix Door Controller Cosec Vega Faxq