
Documentation of a broken access control vulnerability in TCS Cognix Recon Client v3.0, detailing CWE-862/639, affected endpoints, and remediation timeline.
A broken access control vulnerability was identified in Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.
The issue allowed authenticated users to reset passwords of arbitrary user accounts by submitting crafted API requests without proper authorization validation.
The vulnerability resulted from insufficient ownership verification and missing authorization checks within the password reset workflow.
Tata Consultancy Services (TCS)
Cognix Recon Client – Version 3.0
Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS
The vulnerability was responsibly disclosed to Tata Consultancy Services (TCS).
The vendor acknowledged the finding and implemented corrective measures.
TCS implemented strict authorization and ownership validation controls within the password reset functionality.
The vulnerability has been validated as remediated in the currently deployed version of the product.