Weintek Weincloud Weak Password Recovery Mechanism for Forgotten Password
CVE-2023-35134

7.4HIGH

Key Information:

Vendor

Weintek

Status
Vendor
CVE Published:
19 July 2023

What is CVE-2023-35134?

The vulnerability in Weintek Weincloud v0.13.6 allows attackers to exploit the JSON Web Token (JWT) mechanism, enabling unauthorized password resets for user accounts. By leveraging this flaw, attackers could gain access to accounts without the need for valid authentication, posing significant security risks to affected users.

Affected Version(s)

Weincloud 0 <= 0.13.6

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

​Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
.