Vulnerabilities > CVE-2017-3215 - Insufficient Session Expiration vulnerability in Milwaukee One-Key
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |