VulnerabilityModified
CVE-2023-35794
An issue was discovered in Cassia Access Controller 2.1.1.2303271039.
HIGH 8.8EPSS 0.94%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cassianetworks/access controller
- Source
- cve@mitre.org
References
- https://blog.kscsc.online/cves/202335794/md.html
- https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-HijackingExploit, Third Party Advisory
- https://www.cassianetworks.com/products/iot-access-controller/Product
- https://blog.kscsc.online/cves/202335794/md.html
- https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-HijackingExploit, Third Party Advisory
- https://www.cassianetworks.com/products/iot-access-controller/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.