Lucene search

K
cvelistTR-CERTCVELIST:CVE-2023-3048
HistoryJun 13, 2023 - 11:44 a.m.

CVE-2023-3048 IDOR in TMT's Lockcell

2023-06-1311:44:32
CWE-639
TR-CERT
www.cve.org
tmt lockcell
authorization bypass
authentication abuse
vulnerability
idor
cve-2023-3048
lockcell: before 15

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.0%

Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass.This issue affects Lockcell: before 15.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Lockcell",
    "vendor": "TMT",
    "versions": [
      {
        "lessThan": "15",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.0%

Related for CVELIST:CVE-2023-3048