Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trimble
Trimble tm4web |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:trimble:tm4web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trimble
Trimble tm4web |
|
| Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access code and use this access code to register a valid account. via a PUT /inc/tm_ajax.msw request. If the access code was used to create an Administrator account, attackers are also able to register new Administrator accounts with full privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-08T15:10:45.477Z
Reserved: 2023-02-27T00:00:00.000Z
Link: CVE-2023-27195
Updated: 2024-11-08T05:03:06.273Z
Status : Deferred
Published: 2024-11-08T05:15:05.570
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-27195
No data.
OpenCVE Enrichment
No data.