The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
FeverWarn and the associated cloud service were pandemic-specific products for elevated body temperature scanning, discontinued by MachineSense prior to the end of the pandemic. They are no longer available, and there will be no future availability or upgrades. MachineSense is not aware of any current users of FeverWarn. Users of the affected product are encouraged to contact MachineSense https://machinesense.com/pages/about-machinesense for additional information.
Fri, 06 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-06-06T17:26:50.942Z
Reserved: 2023-11-30T20:38:25.990Z
Link: CVE-2023-49617

Updated: 2024-08-02T22:01:25.999Z

Status : Modified
Published: 2024-02-01T23:15:10.227
Modified: 2024-11-21T08:33:38.343
Link: CVE-2023-49617

No data.

No data.