CVE-2022-3083

All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-07 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:landisgyr:e850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:landisgyr:e850:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values. All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values.

10 Feb 2023, 16:43

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-07 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-07 - Third Party Advisory, US Government Resource
CPE cpe:2.3:h:landisgyr:e850:-:*:*:*:*:*:*:*
cpe:2.3:o:landisgyr:e850_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-784 CWE-565
First Time Landisgyr e850 Firmware
Landisgyr
Landisgyr e850

01 Feb 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-01 21:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3083

Mitre link : CVE-2022-3083

CVE.ORG link : CVE-2022-3083


JSON object : View

Products Affected

landisgyr

  • e850_firmware
  • e850
CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking

CWE-784

Reliance on Cookies without Validation and Integrity Checking in a Security Decision