Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-121-01 | us government resource |
https://service.amtelco.com/INFINITY/MSM/MSM6.2SecurityBriefing.pdf |