The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
References
Link | Resource |
---|---|
https://duo.com/blog/bug-hunting-drilling-into-the-internet-of-things-iot | Third Party Advisory |
https://duo.com/blog/bug-hunting-drilling-into-the-internet-of-things-iot | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://duo.com/blog/bug-hunting-drilling-into-the-internet-of-things-iot - Third Party Advisory |
Information
Published : 2017-06-20 00:29
Updated : 2024-11-21 03:25
NVD link : CVE-2017-3215
Mitre link : CVE-2017-3215
CVE.ORG link : CVE-2017-3215
JSON object : View
Products Affected
milwaukee
- one-key
CWE
CWE-613
Insufficient Session Expiration