Impact
ntopng releases up to 6.6 generate HTTP session identifiers using a weak, time‑seeded pseudo‑random number generator during session creation. Fresh authenticated logins can receive deterministic or colliding session cookies when timing is controlled by an attacker, allowing the attacker to hijack authenticated sessions and impersonate the legitimate user. The flaw is a Predictable Session Identifier weakness (CWE-341).
Affected Systems
Any host running ntopng 6.6 or earlier with the web interface exposed is vulnerable. The issue exists in all releases through 6.6 and is fixed in later versions.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. However, the impact of session hijacking is severe; an attacker who can predict or force a collision can immediately assume a user’s privileges. The CVSS score of 9.8 indicates a high severity of this flaw. The risk is therefore high enough that organizations should remediate promptly despite the low exploitation probability.
OpenCVE Enrichment