Impact
A low privileged remote attacker can hijack an active administrative session without knowing the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. The vulnerability stems from improper log handling that discloses sensitive session information, classified as CWE-532.
Affected Systems
Frauscher Sensortechnik FDS 102 is affected by this flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of this flaw, while the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. An attacker with low privileges can acquire session identifiers by downloading error logs, enabling session hijacking without additional credentials. No further conditions are noted in the description.
OpenCVE Enrichment