Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.
Solution:
Workaround:
The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03 | us government resource third party advisory mitigation |