An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user. | An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user. |
Fri, 28 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 28 Mar 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user. | |
Title | Improper Authentication vulnerability in saTECH BCU | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-04T12:46:30.162Z
Reserved: 2025-03-27T10:59:41.167Z
Link: CVE-2025-2859

Updated: 2025-03-28T13:38:15.288Z

Status : Awaiting Analysis
Published: 2025-03-28T14:15:20.810
Modified: 2025-04-04T13:15:46.493
Link: CVE-2025-2859

No data.