Описание
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.13.0_va (включая)
cpe:2.3:o:honeywell:tuxedo_touch:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00381
Низкий
5 Medium
CVSS2
Дефекты
CWE-284
Связанные уязвимости
github
больше 3 лет назад
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.
EPSS
Процентиль: 59%
0.00381
Низкий
5 Medium
CVSS2
Дефекты
CWE-284