SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1148

An authenticated attacker could maintain system access due to session fixation after a user password change.

MEDIUM 6.5EPSS 0.76%

Does this matter?

Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.

Description

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.76% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-384
Affected
tenable/nessus
Source
vulnreport@tenable.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.