SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-1534

mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session…

LOW 2.1EPSS 0.70%

Does this matter?

Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.

Description

mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.70% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-384
Affected
apache/http server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.