An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.
An attacker can exploit a vulnerability in the login.html component of the Vehicle Management System to obtain a higher privilege level than they are entitled to. The attack vector is network-based (AV:N), requires no prior privileges (PR:N) or user interaction (UI:N), which means that the attack can be conducted remotely by anyone with access to the system's web interface.
A successful attack leads to the attacker obtaining elevated privileges in the system, which may result in complete takeover of the application, unauthorized access to vehicle and user data, and violation of system confidentiality, integrity, and availability.
Apply patches available from the manufacturer according to references. Until the update is applied, it is recommended to restrict access to the system's web interface exclusively to trusted networks or IP addresses through firewall or access control mechanisms.
Vehicle Management System version 7.31.0.3_20230412
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H