Description
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version
Credits
Forescout Technologies reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-105-04