Vulnerability Description
F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Analytics | 11.0.0 |
Related Weaknesses (CWE)
References
- http://support.f5.com/kb/en-us/solutions/public/14000/300/sol14334.htmlExploitVendor Advisory
- http://www.securityfocus.com/bid/68792
- http://support.f5.com/kb/en-us/solutions/public/14000/300/sol14334.htmlExploitVendor Advisory
- http://www.securityfocus.com/bid/68792
FAQ
What is CVE-2013-7408?
CVE-2013-7408 is a vulnerability with a CVSS score of 7.5 (HIGH). F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value.
How severe is CVE-2013-7408?
CVE-2013-7408 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-7408?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Analytics.