Improper Session Token Expiration in Dígitro NGC Explorer
CVE-2025-4528
5.3MEDIUM
What is CVE-2025-4528?
A vulnerable condition exists in Dígitro NGC Explorer versions up to 3.44.15, where improper handling of session tokens can lead to unintentional session expiration. This flaw permits potential attackers to exploit the system remotely, which may result in users being unexpectedly logged out. Despite early notification to the vendor regarding this issue, no response has been received, raising concerns about the urgency of addressing such vulnerabilities.
Affected Version(s)
NGC Explorer 3.44.0
NGC Explorer 3.44.1
NGC Explorer 3.44.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
j369 (VulDB User)
