The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Geo++_gncaster | Geopp | * | 1.4.0.7 (including) |
Geo++_gncaster | Geopp | 1.4.0.0 (including) | 1.4.0.0 (including) |