Description


Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.

Weaknesses



CWE-330


CWE-330

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-10T11:15:10.927Z

3 years ago

Last modified

2024-11-21T06:25:20.673Z

1 year ago