VulnerabilityModified
CVE-2017-14007
The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse an old session for authorization.
MEDIUM 5.6EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse an old session for authorization.
- CVSS 3.0
- 5.6 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-613
- Affected
- prominent/multiflex m10a controller firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/101259Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/101259Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.