CVE-2022-30623

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
18/07/2022
Last modified:
23/07/2022

Description

The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:chcnav:p5e_gnss_firmware:4.1:*:*:*:*:*:*:*
cpe:2.3:o:chcnav:p5e_gnss_firmware:4.2:*:*:*:*:*:*:*
cpe:2.3:h:chcnav:p5e_gnss:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools