CVE-2017-3215
MEDIUMMilwaukee One-key - Insufficient Session Expiration
Title source: ruleDescription
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
Scores
CVSS v3
5.3
EPSS
0.0020
EPSS Percentile
41.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-613
Status
published
Products (2)
milwaukee/one-key
Milwaukee Tool/ONE-KEY
< unspecified
Published
Jun 20, 2017
Tracked Since
Feb 18, 2026