CVE-2023-2904

CVE-2023-2904

The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through
5.11.3 are vulnerable to manipulation within web fields in the
application programmable interface (API). An attacker could log in using
account credentials available through a request generated by an
internal user and then manipulate the visitor-id within the web API to
access the personal data of other users. There is no limit on the number
of requests that can be made to the HID SAFE Web Server, so an attacker
could also exploit this vulnerability to create a denial-of-service
condition.

Source: CVE-2023-2904

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다