Session Fixation Vulnerability in Belden Hirschmann Network Switches
CVE-2018-5465

8.8HIGH

What is CVE-2018-5465?

A session fixation vulnerability has been detected in the web interfaces of various Belden Hirschmann switches, including the RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform. This issue may allow an attacker to hijack active web sessions by exploiting the session management process. Proper security measures should be taken to mitigate risks associated with unauthorized access to network devices through session manipulation.

Affected Version(s)

Hirschmann Automation and Control GmbH Classic Platform Switches Hirschmann Automation and Control GmbH Classic Platform Switches

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.