Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9c3-4c2f-4w5r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen.

DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen.

EPSS

Процентиль: 87%
0.032
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen.

EPSS

Процентиль: 87%
0.032
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-565