Description
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 3.6.0
Credits
Forescout Technologies reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-105-04