Vulnerabilities > CVE-2022-45636 - Missing Authorization vulnerability in Megafeis Bofei Dbd+ 1.4.3/1.4.4
Attack vector
ADJACENT_NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- https://github.com/WithSecureLabs/megafeis-palm/tree/main/CVE-2022-45636
- https://github.com/WithSecureLabs/megafeis-palm/tree/main/CVE-2022-45636
- https://labs.withsecure.com/advisories/insecure-authorization-scheme-for-api-requests-in-dbd--mobile-co
- https://labs.withsecure.com/advisories/insecure-authorization-scheme-for-api-requests-in-dbd--mobile-co