9.6
CVE-2026-8670
- EPSS 0.22%
- Veröffentlicht 22.05.2026 13:12:52
- Zuletzt bearbeitet 02.06.2026 15:01:03
- Quelle vulnerability@ncsc.ch
- CVE-Watchlists
- Unerledigt
Insecure session handling on metrics web server
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.118 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| vulnerability@ncsc.ch | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://support.avantra.com/hc/en-us/articles/5533929912351