VulnerabilityModified
CVE-2018-1148
An authenticated attacker could maintain system access due to session fixation after a user password change.
MEDIUM 6.5EPSS 0.76%
Does this matter?
Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.
Description
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- tenable/nessus
- Source
- vulnreport@tenable.com
References
- http://www.securitytracker.com/id/1040918Third Party Advisory, VDB Entry
- https://www.tenable.com/security/tns-2018-05Vendor Advisory
- http://www.securitytracker.com/id/1040918Third Party Advisory, VDB Entry
- https://www.tenable.com/security/tns-2018-05Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.