CVE-2022-45636
HIGH 8.1EPSS 0.7%
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS
- 0.69% chance of exploitation in the next 30 days, 50th percentile
- Published
- 2023-03-21
- Updated
- 2025-02-26
Proof-of-concept exploits (2)
- WithSecureLabs/megafeis-palm/tree/main/CVE-2022-45636
- https://labs.withsecure.com/advisories/insecure-authorization-scheme-for-api-requests-in-…