Description
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49125 | SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7100-7a15c-1.html |
|
History
Thu, 09 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-01-09T14:39:00.938Z
Reserved: 2022-11-29T00:00:00.000Z
Link: CVE-2022-46308
Updated: 2024-08-03T14:31:46.278Z
Status : Modified
Published: 2023-06-02T11:15:09.913
Modified: 2024-11-21T07:30:21.387
Link: CVE-2022-46308
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD