PT-2018-3425 · Belden · Belden Hirschmann Rs+7

Damir Zainullin

+4

·

Published

2018-03-06

·

Updated

2019-10-09

·

CVE-2018-5465

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches (affected versions not specified)
Description: A Session Fixation issue was discovered in the web interface of the affected switches, which may allow an attacker to hijack web sessions. The vulnerability is related to incorrect session management, potentially enabling a remote attacker to gain unauthorized access and intercept web sessions.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00975
CVE-2018-5465

Affected Products

Belden Hirschmann Rs
Mach100
Mach1000
Mach4000
Ms
Octopus Classic Platform Switches
Rsb
Rsr