Impact
The vulnerability in the login page of docuFORM Managed Print Service Client 11.11c allows a session fixation attack. By manipulating the session identifier before authentication, an attacker can force a victim to use a known session ID, potentially gaining unauthorized access to the application and executing actions with the victim’s privileges. The likely attack vector is that a crafted request is sent to the login endpoint, setting a pre‑supplied session ID before the user logs in.
Affected Systems
The vulnerability affects docuFORM Managed Print Service Client version 11.11c. The release notes mention only this version, but earlier releases sharing the same authentication mechanism might also be vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Exploitation can occur over the network when the client’s login endpoint is reachable, typically via standard web ports. The attack requires no special privileges beyond the ability to submit a crafted request that sets a session identifier. The vulnerability is not listed in the CISA KEV catalog. Because the EPSS score is not available, the likelihood of exploitation in the wild is unknown; if the client is exposed to an untrusted network, the vulnerability remains a notable risk.
OpenCVE Enrichment