Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3gr-956r-2x26

Опубликовано: 01 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.

All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.

EPSS

Процентиль: 5%
0.00021
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-565
CWE-784

Связанные уязвимости

CVSS3: 3.9
nvd
около 3 лет назад

All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.

EPSS

Процентиль: 5%
0.00021
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-565
CWE-784