go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

SGUDA U-Lock - Broken Access Control

TVN ID TVN-202211009
CVE ID CVE-2022-46308
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Contact tech support from SGUDA
Description SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information.
Solution Contact tech support from SGUDA
Credit Terrynini (DEVCORE)
Public Date 2023-05-11
Top