Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-36483

Description

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlierwhich allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.

POC

Reference

No PoCs from references.

Github

- https://github.com/NaInSec/CVE-LIST

- https://github.com/fkie-cad/nvd-json-data-feeds