PT-2024-18174 · Sagemcom · Sagemcom Fast3686 V2

David Utón

·

Published

2024-03-14

·

Updated

2024-03-19

·

CVE-2024-1623

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sagemcom FAST3686 V2 Vodafone router (affected versions not specified)
Description The issue is related to an insufficient session timeout in the Sagemcom FAST3686 V2 Vodafone router. This could allow a local attacker to access the administration panel without requiring login credentials. The vulnerability is possible because the 'Login.asp' and 'logout.asp' files do not handle session details correctly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-1623

Affected Products

Sagemcom Fast3686 V2