Vulnerability Description
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Masmobile Asp.Net Services | <= 1.9 |
| Honeywell | Masmobile Classic | <= 1.7.24 |
Related Weaknesses (CWE)
References
- https://www.corporate.carrier.com/product-security/advisories-resources/Not ApplicableVendor Advisory
- https://www.corporate.carrier.com/product-security/advisories-resources/Not ApplicableVendor Advisory
FAQ
What is CVE-2023-36483?
CVE-2023-36483 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote atta...
How severe is CVE-2023-36483?
CVE-2023-36483 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36483?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Masmobile Asp.Net Services, Honeywell Masmobile Classic.