go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3

TVN ID TVN-202209004
CVE ID CVE-2022-39031
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products Smart eVision ver.2022.02.21
Description Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only.
Solution Update Smart eVision version to 2022.06.16
Credit Gary Tan, Zac Wang (Talent-Jump)
Public Date 2022-09-28
Top