Description
The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the cookie header to generate "legitimate" requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45609 | The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the cookie header to generate "legitimate" requests. |
References
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-12T17:54:32.972Z
Reserved: 2023-09-12T23:06:14.688Z
Link: CVE-2023-41089
Updated: 2024-08-02T18:46:11.906Z
Status : Modified
Published: 2023-10-19T19:15:15.513
Modified: 2024-11-21T08:20:32.500
Link: CVE-2023-41089
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD