CVE-2023-36483
EUVD-2023-4043216.03.2024, 05:15
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| honeywell | masmobile_asp.net_services | 𝑥 ≤ 1.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration