8.8
CVE-2023-34656
- EPSS 0.08%
- Veröffentlicht 29.06.2023 15:15:09
- Zuletzt bearbeitet 27.11.2024 15:15:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Video Management System Project ≫ Video Management System Version >= 3.1 <= 4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.249 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.