2024-03-21 23:03:27 +00:00

59 lines
2.4 KiB
JSON

{
"id": "CVE-2023-36483",
"sourceIdentifier": "productsecurity@carrier.com",
"published": "2024-03-16T05:15:18.577",
"lastModified": "2024-03-21T22:15:10.573",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android\u00a0 version 1.16.18 and earlier and \n\nMASmobile Classic iOS version 1.7.24 and earlier\n\nwhich allows remote attackers to retrieve sensitive data\u00a0 including customer data, security system status, and event history.\n"
},
{
"lang": "es",
"value": "Se descubri\u00f3 una omisi\u00f3n de autorizaci\u00f3n en la aplicaci\u00f3n Carrier MASmobile Classic hasta la versi\u00f3n 1.16.18 para Android, la aplicaci\u00f3n MASmobile Classic hasta la 1.7.24 para iOS y los servicios MAS ASP.Net hasta la 1.9. Esto se puede lograr mediante la predicci\u00f3n de ID de sesi\u00f3n, lo que permite a atacantes remotos recuperar datos confidenciales, incluidos datos de clientes, estado del sistema de seguridad e historial de eventos. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante. Los productos afectados no pueden simplemente actualizarse; deben eliminarse, pero pueden reemplazarse por otro software de Carrier como se explica en el aviso de Carrier."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "productsecurity@carrier.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "productsecurity@carrier.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"references": [
{
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"source": "productsecurity@carrier.com"
}
]
}