The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T17:54:12.663Z

Reserved: 2013-06-29T00:00:00Z

Link: CVE-2013-4732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-06-30T19:28:10.173

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-4732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.