Authentication Bypass Vulnerability in Link to Windows Service (Version 2.3.04.1 and earlier) Allows Device Lock

Authentication Bypass Vulnerability in Link to Windows Service (Version 2.3.04.1 and earlier) Allows Device Lock

CVE-2022-28790 · LOW Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

Learn more about our Web Application Penetration Testing UK.