The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
References
Link | Resource |
---|---|
https://duo.com/blog/bug-hunting-drilling-into-the-internet-of-things-iot | Third Party Advisory |
Configurations
Information
Published : 2017-06-19 17:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-3215
Mitre link : CVE-2017-3215
JSON object : View
CWE
CWE-613
Insufficient Session Expiration
Products Affected
milwaukee
- one-key