CVE Vulnerabilities

CVE-2023-49259

Predictable from Observable State

Published: Jan 12, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

Weakness

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Affected Software

Name Vendor Start Version End Version
H8951-4g-esp_firmware Hongdian * 2310271149 (excluding)

Potential Mitigations

References