CVE Vulnerabilities

CVE-2024-39275

Use of Persistent Cookies Containing Sensitive Information

Published: Sep 27, 2024 | Modified: Oct 07, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.

Weakness

The web application uses persistent cookies, but the cookies contain sensitive information.

Affected Software

Name Vendor Start Version End Version
Adam-5630_firmware Advantech * 2.5.2 (excluding)

Potential Mitigations

References