The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.
Solution:
This weakness has been deprecated because it covered redundant concepts already described in CWE-287.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-12-362-01 | |
http://www.us-cert.gov/control_systems/pdf/ICSA-12-362-01.pdf | us government resource |