HTTP: LG LED Assistant API changePw Unverified Password Reset

This signature detects attempts to exploit a known vulnerability against LG LED Assistant. A successful attack can lead to security bypass.

Extended Description

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

Affected Products

Lg lg_led_assistant

Short Name
HTTP:CTS:LG-LED-CHANGEPW-RESET
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
API Assistant CVE-2024-2862 LED LG Password Reset Unverified changePw
Release Date
05/07/2024
Supported Platforms

srx-branch-12.3

srx-branch-19.3

vsrx3bsd-19.2

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

srx-19.4

vsrx-12.3

srx-12.3

vsrx-19.2

srx-19.3

Sigpack Version
3796
False Positive
Unknown
Vendors

Lg

Found a potential security threat?