Home
HIGH: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NDefault status
unaffected
Any version before 20.02.2025
affected
Description
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
Problem types
CWE-669 Incorrect Resource Transfer Between Spheres
Product status
Any version before 20.02.2025
Credits
Jannik Zimmer
References
cert.vde.com/en/advisories/VDE-2025-010