A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the file suanfa.py of the component Password Reset Handler. The manipulation leads to authorization bypass. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Sovell
Sovell smart Canteen System
CPEs cpe:2.3:a:sovell:smart_canteen_system:*:*:*:*:*:*:*:*
Vendors & Products Sovell
Sovell smart Canteen System
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Oct 2024 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the file suanfa.py of the component Password Reset Handler. The manipulation leads to authorization bypass. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Title Sovell Smart Canteen System Password Reset suanfa.py Check_ET_CheckPwdz201 authorization
Weaknesses CWE-639
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-10-06T11:31:04.369Z

Updated: 2024-10-07T13:49:11.679Z

Reserved: 2024-10-05T16:57:06.367Z

Link: CVE-2024-9554

cve-icon Vulnrichment

Updated: 2024-10-07T13:49:05.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-06T12:15:08.117

Modified: 2024-10-07T17:47:48.410

Link: CVE-2024-9554

cve-icon Redhat

No data.