Описание
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:lanatmservice:m3_atm_monitoring_system:6.1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04441
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-613
Связанные уязвимости
github
больше 3 лет назад
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
EPSS
Процентиль: 89%
0.04441
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-613