CVE-2023-36483
MAS (a Carrier brand) MASmobile Classic Authorization Bypass
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and
MASmobile Classic iOS version 1.7.24 and earlier
which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
MAS (a Carrier brand) · MAS ASP.Net ServicesMAS (a Carrier brand) · MASmobile ClassicWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →