SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-9386

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

MEDIUM 6.8EPSS 2.05%

Does this matter?

Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.

Description

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.05% probability · 80th percentile
CISA KEV
Not listed
Affected
zenoss/zenoss core
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.