CVE-2023-36483
MAS (a Carrier brand) MASmobile Classic Authorization Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and
MASmobile Classic iOS version 1.7.24 and earlier
which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
Se descubrió una omisión de autorización en la aplicación Carrier MASmobile Classic hasta la versión 1.16.18 para Android, la aplicación MASmobile Classic hasta la 1.7.24 para iOS y los servicios MAS ASP.Net hasta la 1.9. Esto se puede lograr mediante la predicción de ID de sesión, lo que permite a atacantes remotos recuperar datos confidenciales, incluidos datos de clientes, estado del sistema de seguridad e historial de eventos. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante. Los productos afectados no pueden simplemente actualizarse; deben eliminarse, pero pueden reemplazarse por otro software de Carrier como se explica en el aviso de Carrier.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-06-22 CVE Reserved
- 2024-03-16 CVE Published
- 2024-03-16 EPSS Updated
- 2024-08-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
- CAPEC-59: Session Credential Falsification through Prediction
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
MAS (a Carrier Brand) Search vendor "MAS (a Carrier Brand)" | MASmobile Classic Search vendor "MAS (a Carrier Brand)" for product "MASmobile Classic" | >= 1.0.0 <= 1.16.18 Search vendor "MAS (a Carrier Brand)" for product "MASmobile Classic" and version " >= 1.0.0 <= 1.16.18" | en |
Affected
| ||||||
MAS (a Carrier Brand) Search vendor "MAS (a Carrier Brand)" | MASmobile Classic Search vendor "MAS (a Carrier Brand)" for product "MASmobile Classic" | >= 1.0.0 <= 1.7.24 Search vendor "MAS (a Carrier Brand)" for product "MASmobile Classic" and version " >= 1.0.0 <= 1.7.24" | en |
Affected
| ||||||
MAS (a Carrier Brand) Search vendor "MAS (a Carrier Brand)" | MAS ASP.Net Services Search vendor "MAS (a Carrier Brand)" for product "MAS ASP.Net Services" | >= 1.0 <= 1.9 Search vendor "MAS (a Carrier Brand)" for product "MAS ASP.Net Services" and version " >= 1.0 <= 1.9" | en |
Affected
|