CVE-2022-1368

CVE-2022-1368

The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session. This could allow an attacker to escalate privileges to match those of the compromised account.

Source: CVE-2022-1368

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다