Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76f5-r74w-9h63

Опубликовано: 12 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

EPSS

Процентиль: 35%
0.00145
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

CVSS3: 4.9
fstec
около 1 года назад

Уязвимость в веб-интерфейса управления программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), связанная с неверным сроком действия сеанса, позволяющая нарушителю сохранить сеанс после удаления учетной записи

EPSS

Процентиль: 35%
0.00145
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-613