Lucene search

K
nvd[email protected]NVD:CVE-2023-23304
HistoryMay 23, 2023 - 8:15 p.m.

CVE-2023-23304

2023-05-2320:15:09
web.nvd.nist.gov
3
garminos
ciq api
permission flaw
sensorhistory
unauthorized access

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9

Confidence

High

EPSS

0.001

Percentile

49.0%

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the Toybox.SensorHistory module without permission. A malicious application could call any functions from the Toybox.SensorHistory module without the user’s consent and disclose potentially private or sensitive information.

Affected configurations

Nvd
Node
garminconnect-iqRange2.1.04.1.7
VendorProductVersionCPE
garminconnect-iq*cpe:2.3:a:garmin:connect-iq:*:*:*:*:*:*:*:*

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9

Confidence

High

EPSS

0.001

Percentile

49.0%

Related for NVD:CVE-2023-23304