CVE-2024-36388
02.06.2024, 14:15
MileSight DeviceHub - CWE-305 Missing Authentication for Critical FunctionEnginsight
Vendor | Product | Version |
---|---|---|
milesight | devicehub | 3.0.1-r1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-305 - Authentication Bypass by Primary WeaknessThe authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.