An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.
History

Tue, 01 Oct 2024 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Circutor q-smt
Circutor q-smt Firmware
CPEs cpe:2.3:h:circutor:q-smt:-:*:*:*:*:*:*:*
cpe:2.3:o:circutor:q-smt_firmware:1.0.4:*:*:*:*:*:*:*
Vendors & Products Circutor q-smt
Circutor q-smt Firmware

Wed, 18 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor circutor Q Smt
CPEs cpe:2.3:a:circutor:circutor_q_smt:*:*:*:*:*:*:*:*
Vendors & Products Circutor
Circutor circutor Q Smt
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 12:00:00 +0000

Type Values Removed Values Added
Description An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.
Title Insufficient Session Expiration vulnerability on CIRCUTOR Q-SMT
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-09-18T11:54:47.337Z

Updated: 2024-09-18T13:14:00.252Z

Reserved: 2024-09-16T10:20:29.982Z

Link: CVE-2024-8888

cve-icon Vulnrichment

Updated: 2024-09-18T13:13:52.956Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-18T12:15:03.520

Modified: 2024-10-01T19:30:35.400

Link: CVE-2024-8888

cve-icon Redhat

No data.