An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Feb 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 05 Feb 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 30 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-384 | |
| Metrics |
ssvc
|
Thu, 30 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: symantec
Published: 2025-01-30T18:24:32.902Z
Updated: 2025-02-05T04:50:21.091Z
Reserved: 2025-01-22T08:29:34.304Z
Link: CVE-2025-24502
Updated: 2025-01-30T19:22:53.204Z
Status : Awaiting Analysis
Published: 2025-01-30T19:15:14.863
Modified: 2025-02-05T05:15:11.300
Link: CVE-2025-24502
No data.