PT-2013-5165 · Digital Alert Systems+1 · Dasdec+1

Published

2013-06-29

·

Updated

2024-08-06

·

CVE-2013-4732

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Digital Alert Systems DASDEC EAS device versions 2.0-2 through 2.0-2 Monroe Electronics R189 One-Net EAS device versions 2.0-2 through 2.0-2
Description The administrative web server uses predictable session ID values, making it easier for remote attackers to hijack sessions by sniffing the network.
Recommendations For Digital Alert Systems DASDEC EAS device version 2.0-2, consider implementing additional session security measures to prevent hijacking. For Monroe Electronics R189 One-Net EAS device version 2.0-2, as the issue could not be reproduced, monitor the device for any potential security issues and apply any future patches or updates that may address related problems.

Fix

Weakness Enumeration

Related Identifiers

CVE-2013-4732

Affected Products

Dasdec
R189 One-Net