"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Metrics
Affected Vendors & Products
References
History
Tue, 10 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Nov 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. | |
Weaknesses | CWE-288 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-11-26T07:37:44.549Z
Updated: 2024-12-10T14:58:18.708Z
Reserved: 2024-05-22T09:00:05.257Z
Link: CVE-2024-33610
Vulnrichment
Updated: 2024-12-10T14:58:15.426Z
NVD
Status : Received
Published: 2024-11-26T08:15:05.810
Modified: 2024-11-26T08:15:05.810
Link: CVE-2024-33610
Redhat
No data.