Session Management Flaw in ESPEC North America Web Controller
CVE-2025-27847

4.3MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2025

What is CVE-2025-27847?

In versions prior to 3.3.8 of the ESPEC North America Web Controller, a significant issue exists where user session privileges are not effectively revoked upon logout. This flaw can allow unauthorized users to maintain access to previously authorized functionalities, posing potential risks to sensitive data and overall application integrity. Users of the affected product are advised to upgrade to the latest version to mitigate any security risks associated with this vulnerability.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.