PT-2010-1246 · Amsn · Amsn
Published
2010-04-20
·
Updated
2010-06-03
·
CVE-2008-7255
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
amsn versions prior to 0.97.1
Description
The issue allows physically proximate attackers to hijack a session by visiting an unattended workstation, as the password is saved after logout.
Recommendations
For versions prior to 0.97.1, update to version 0.97.1 or later to resolve the issue. As a temporary workaround, consider clearing the saved password after each session or ensuring the workstation is properly secured when unattended.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amsn