MEDIUM · 6.5

CVE-2023-36483

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote atta...

Vulnerability Description

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HoneywellMasmobile Asp.Net Services<= 1.9
HoneywellMasmobile Classic<= 1.7.24

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-36483?

CVE-2023-36483 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote atta...

How severe is CVE-2023-36483?

CVE-2023-36483 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-36483?

Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Masmobile Asp.Net Services, Honeywell Masmobile Classic.