PatchSiren cyber security CVE debrief
CVE-2023-6724 Software Engineering Consultancy Machine Equipment Limited Company CVE debrief
A high-severity authorization bypass vulnerability exists in the Hearing Tracking System mobile application developed by Software Engineering Consultancy Machine Equipment Limited Company (Simgesel). The flaw, categorized as CWE-639 (Authorization Bypass Through User-Controlled Key), enables authentication abuse by allowing attackers to manipulate user-controlled keys to bypass authorization checks. The vulnerability affects Android versions up to and including 1.0 and iOS versions prior to 7.0. The issue was disclosed publicly on February 9, 2024, with the NVD record subsequently modified on May 20, 2026. Turkish cybersecurity authorities (USOM and siberguvenlik.gov.tr) issued coordinated advisories under identifier TR-24-0099. No known exploitation in ransomware campaigns has been documented, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Software Engineering Consultancy Machine Equipment Limited Company
- Product
- Hearing Tracking System
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-09
- Original CVE updated
- 2026-05-20
- Advisory published
- 2024-02-09
- Advisory updated
- 2026-05-20
Who should care
Organizations deploying Simgesel Hearing Tracking System for employee or patient hearing monitoring; healthcare facilities using mobile audiometric tracking; security teams managing mobile application portfolios; compliance officers responsible for health data protection regulations
Technical summary
The vulnerability stems from improper authorization validation where user-controlled keys can be manipulated to circumvent authentication controls. The CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that an attacker with low privileges can exploit this remotely without user interaction, resulting in complete compromise of confidentiality, integrity, and availability. The attack surface is the mobile application's API or backend services that trust client-provided keys for authorization decisions without adequate server-side validation.
Defensive priority
HIGH
Recommended defensive actions
- Update Hearing Tracking System mobile application to iOS version 7.0 or later, or Android version beyond 1.0
- Review and validate all authorization mechanisms implementing user-controlled keys for proper server-side verification
- Monitor authentication logs for anomalous access patterns indicating potential authorization bypass attempts
- Coordinate with mobile device management (MDM) solutions to enforce minimum application version policies
- Subscribe to vendor security communications and USOM advisories for future security updates
Evidence notes
Vulnerability classification derived from NVD CPE data and USOM advisory TR-24-0099. CVSS 3.1 vector confirms network attack vector with low attack complexity and high impact confidentiality, integrity, and availability. Affected version ranges explicitly defined in CPE criteria: Android ≤1.0, iOS <7.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-6724 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-6724
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-6724 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-6724
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-0099
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-24-0099
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.