CVE-2023-3050
13.06.2023, 12:15
Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15.Enginsight
Vendor | Product | Version |
---|---|---|
tmtmakine | lockcell_firmware | 𝑥 < 15.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-784 - Reliance on Cookies without Validation and Integrity Checking in a Security DecisionThe application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.
- CWE-565 - Reliance on Cookies without Validation and Integrity CheckingThe application relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
References