{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"Bishoy Roufael","summary":"reporting"}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Up until October 5th, 2022 the ease2pay API used by Miele's \"AppWash\" MobileApp was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.","title":"Summary"},{"category":"description","text":"The evaluation of the log files by ease2pay did not show any sign of actual exploitation of the vulnerability, extraction of data or misuse.","title":"Impact"},{"category":"description","text":"The ease2pay cloud service used by appWash was fixed on 05.10.2022. The tokens used for session authentication were changed to a secure state of the art solution. All affected tokens have been invalidated and new tokens were issued.\nTherefore, no actions have to be taken by the users.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@miele.com","name":"Miele & Cie KG","namespace":"https://www.miele.com"},"references":[{"category":"self","summary":"VDE-2022-052: Miele: Vulnerability in ease2pay cloud service used by appWash - HTML","url":"https://certvde.com/en/advisories/VDE-2022-052/"},{"category":"self","summary":"VDE-2022-052: Miele: Vulnerability in ease2pay cloud service used by appWash - CSAF","url":"https://miele.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-052.json"},{"category":"external","summary":"Vendor PSIRT","url":"https://www.miele.com"},{"category":"external","summary":"CERT@VDE Security Advisories for Miele & Cie KG","url":"https://certvde.com/en/advisories/vendor/miele/"}],"title":"Miele: Vulnerability in ease2pay cloud service used by appWash","tracking":{"aliases":["VDE-2022-052"],"current_release_date":"2022-11-21T09:00:00.000Z","generator":{"date":"2025-05-05T12:10:12.123Z","engine":{"name":"Secvisogram","version":"2.5.24"}},"id":"VDE-2022-052","initial_release_date":"2022-11-21T09:00:00.000Z","revision_history":[{"date":"2022-11-21T09:00:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"vers:all/*","product":{"name":"appWash by Miele vers:all/*","product_id":"CSAFPID-51001"}}],"category":"product_name","name":"appWash by Miele"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"Miele"}]},"vulnerabilities":[{"cve":"CVE-2022-3589","cwe":{"id":"CWE-639","name":"Authorization Bypass Through User-Controlled Key"},"notes":[{"category":"description","text":"An API Endpoint used by Miele's \"AppWash\" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-51001"]},"remediations":[{"category":"vendor_fix","details":"The ease2pay cloud service used by appWash was fixed on 05.10.2022. The tokens used for session authentication were changed to a secure state of the art solution. All affected tokens have been invalidated and new tokens were issued.\nTherefore, no actions have to be taken by the users.","product_ids":["CSAFPID-51001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":8.1,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":8.1,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["CSAFPID-51001"]}],"title":"CVE-2022-3589"}]}