Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmm5-59wm-x34p

Опубликовано: 13 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

EPSS

Процентиль: 21%
0.00065
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.8
nvd
9 месяцев назад

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

CVSS3: 8.8
fstec
9 месяцев назад

Уязвимость веб-системы управления технологическими процессами SIMATIC PCS neo, связанная с неверным сроком действия сеанса, позволяющая нарушителю перехватить сеанс пользователя

EPSS

Процентиль: 21%
0.00065
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-613