Session Replay Attack Can Bypass Privilege Token Validation in Advantech ADAM-5630

CVE-2024-39275

8.8HIGH

Key Information

Vendor
Advantech
Status
Adam-5630 Firmware
Vendor
CVE Published:
27 September 2024

Summary

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.

Refferences

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.