Логотип exploitDog
bind:CVE-2024-46892
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-46892

Количество 3

Количество 3

nvd логотип

CVE-2024-46892

около 1 года назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-76f5-r74w-9h63

около 1 года назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2024-10321

около 1 года назад

Уязвимость в веб-интерфейса управления программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), связанная с неверным сроком действия сеанса, позволяющая нарушителю сохранить сеанс после удаления учетной записи

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-46892

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-76f5-r74w-9h63

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even after their user account has been disabled.

CVSS3: 4.9
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10321

Уязвимость в веб-интерфейса управления программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), связанная с неверным сроком действия сеанса, позволяющая нарушителю сохранить сеанс после удаления учетной записи

CVSS3: 4.9
0%
Низкий
около 1 года назад

Уязвимостей на страницу