10

CVE-2013-4732

The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network.  NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.04% 0.858
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf
Vendor Advisory
http://www.kb.cert.org/vuls/id/662676
US Government Resource
http://www.kb.cert.org/vuls/id/AAMN-98MU7H
US Government Resource
http://www.kb.cert.org/vuls/id/AAMN-98MUK2
US Government Resource
http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf
Vendor Advisory