PT-2013-5165 · Digital Alert Systems+1 · Dasdec+1
Published
2013-06-29
·
Updated
2024-08-06
·
CVE-2013-4732
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Digital Alert Systems DASDEC EAS device versions 2.0-2 through 2.0-2
Monroe Electronics R189 One-Net EAS device versions 2.0-2 through 2.0-2
Description
The administrative web server uses predictable session ID values, making it easier for remote attackers to hijack sessions by sniffing the network.
Recommendations
For Digital Alert Systems DASDEC EAS device version 2.0-2, consider implementing additional session security measures to prevent hijacking.
For Monroe Electronics R189 One-Net EAS device version 2.0-2, as the issue could not be reproduced, monitor the device for any potential security issues and apply any future patches or updates that may address related problems.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dasdec
R189 One-Net