PT-2018-3425 · Belden · Belden Hirschmann Rs+7
Damir Zainullin
+4
·
Published
2018-03-06
·
Updated
2019-10-09
·
CVE-2018-5465
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches (affected versions not specified)
Description:
A Session Fixation issue was discovered in the web interface of the affected switches, which may allow an attacker to hijack web sessions. The vulnerability is related to incorrect session management, potentially enabling a remote attacker to gain unauthorized access and intercept web sessions.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Belden Hirschmann Rs
Mach100
Mach1000
Mach4000
Ms
Octopus Classic Platform Switches
Rsb
Rsr