A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:o:taphome:core_firmware:-:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Wed, 02 Oct 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 |
Wed, 02 Oct 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2023-07-17T06:14:15.872Z
Updated: 2024-10-30T14:55:16.810Z
Reserved: 2023-05-17T14:21:49.140Z
Link: CVE-2023-2759
Vulnrichment
Updated: 2024-08-02T06:33:05.760Z
NVD
Status : Modified
Published: 2023-07-17T07:15:08.717
Modified: 2024-11-21T07:59:14.180
Link: CVE-2023-2759
Redhat
No data.