The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the cookie header to generate "legitimate" requests.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2023-10-19T18:13:25.005Z
Updated: 2024-09-12T17:54:32.972Z
Reserved: 2023-09-12T23:06:14.688Z
Link: CVE-2023-41089
Vulnrichment
Updated: 2024-08-02T18:46:11.906Z
NVD
Status : Analyzed
Published: 2023-10-19T19:15:15.513
Modified: 2023-10-25T13:38:19.127
Link: CVE-2023-41089
Redhat
No data.