Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.
History

Thu, 09 Jan 2025 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-384
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Thu, 31 Oct 2024 20:00:00 +0000

Type Values Removed Values Added
Description In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.

Wed, 30 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Netadmin
Netadmin netadmin
Weaknesses CWE-384
CPEs cpe:2.3:a:netadmin:netadmin:*:*:*:*:*:*:*:*
Vendors & Products Netadmin
Netadmin netadmin
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-29T00:00:00

Updated: 2025-01-09T17:25:23.481Z

Reserved: 2024-10-10T00:00:00

Link: CVE-2024-48955

cve-icon Vulnrichment

Updated: 2024-10-30T15:10:36.718Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-29T18:15:05.690

Modified: 2025-01-09T18:15:29.147

Link: CVE-2024-48955

cve-icon Redhat

No data.