Impact
SafeLine through 9.4.1 derives the session‑signing secret for the management console from a time‑seeded math/rand generator. An attacker can determine or approximate the system install time, reconstruct the weak secret offline, and use it to forge valid administrator session cookies. This gives the attacker full administrative control over the managed sites without any prior authentication.
Affected Systems
The vulnerability affects the Chaitin SafeLine appliance up to and including version 9.4.1. Anyone running a SafeLine instance in this release series and exposing the management console to a network where an unauthenticated user can guess the install timestamp is impacted.
Risk and Exploitability
The CVSS score of 9.2 categorizes this flaw as critical. The EPSS score of less than 1% suggests a low probability that existing exploits are actively used, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the remote attack vector is plausible for infrastructure that exposes the management console; an attacker who can infer or guess the install timestamp can replay the session cookie and bypass authentication. The weakness stems from the use of a non‑cryptographic PRNG for a security key (CWE‑338).
OpenCVE Enrichment