Predictable Web Session Token Vulnerability in Digital Watchdog Products
CVE-2026-66372
7.6HIGH
What is CVE-2026-66372?
The vulnerability arises from the use of insufficiently random values in the generation of web session tokens within various Digital Watchdog products. This leads to predictable session tokens, compromising the integrity of the session management process. The limited entropy of the generated tokens bounds them to the seed space, making it feasible for an attacker to predict valid session tokens and allowing unauthorized access to sensitive functionalities.
Affected Version(s)
VA1G4 Recorder All
VG4 Recorder All
VMAX A1 G4 DVR All
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Scot Berner of TrustedSec reported this vulnerability to CISA.
