Metrics
Affected Vendors & Products
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Thu, 09 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-384 | |
| Metrics |
cvssV3_1
|
Thu, 31 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied. |
Wed, 30 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netadmin
Netadmin netadmin |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:netadmin:netadmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netadmin
Netadmin netadmin |
|
| Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-29T00:00:00.000Z
Updated: 2025-03-18T18:37:32.449Z
Reserved: 2024-10-10T00:00:00.000Z
Link: CVE-2024-48955
Updated: 2024-10-30T15:10:36.718Z
Status : Awaiting Analysis
Published: 2024-10-29T18:15:05.690
Modified: 2025-03-18T19:15:45.317
Link: CVE-2024-48955
No data.