[Japanese] | |
JVNDB-2023-000036 | |
API server of TONE Family vulnerable to authentication bypass using an alternate path | |
Overview | |
API server of TONE Family provided by DREAM TRAIN INTERNET INC. contains an authentication bypass vulnerability using an alternate path (CWE-288). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 5.3 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
This vulnerability exists in API server. This CVSS base score is analyzed as the severity of attacks against API server.
| |
Affected Products | |
| |
DREAM TRAIN INTERNET INC. | |
| |
Impact | |
A remote unauthenticated attacker may login to the management console of the affected service by using E-mail address required when logging into its service. As a result, sensitive information may be viewed and/or configuration settings of the device may be altered with the user privilege. | |
Solution | |
The vulnerability was fixed by the developer on November 2nd, 2022. Users are not required to take any further actions because the fix for this vulnerability was made on the server-side. | |
Vendor Information | |
DREAM TRAIN INTERNET INC. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/04/17 |
Date First Published | 2023/04/17 |
Date Last Updated | 2023/04/17 |