Vulnerability Description
A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface has been identified, which may allow an attacker to hijack web sessions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Belden | Hirschmann Rs20-0900Mmm2Tdau | - |
| Belden | Hirschmann Rs20-0900Nnm4Tdau | - |
| Belden | Hirschmann Rs20-0900Vvm2Tdau | - |
| Belden | Hirschmann Rs20-1600L2L2Sdau | - |
| Belden | Hirschmann Rs20-1600L2M2Sdau | - |
| Belden | Hirschmann Rs20-1600L2S2Sdau | - |
| Belden | Hirschmann Rs20-1600L2T1Sdau | - |
| Belden | Hirschmann Rs20-1600M2M2Sdau | - |
| Belden | Hirschmann Rs20-1600M2T1Sdau | - |
| Belden | Hirschmann Rs20-1600S2M2Sdau | - |
| Belden | Hirschmann Rs20-1600S2S2Sdau | - |
| Belden | Hirschmann Rs20-1600S2T1Sdau | - |
| Belden | Hirschmann Rsr20 | - |
| Belden | Hirschmann Rsr30 | - |
| Belden | Hirschmann Rsb20-0800M2M2Saab | - |
| Belden | Hirschmann Rsb20-0800M2M2Saabe | - |
| Belden | Hirschmann Rsb20-0800M2M2Taab | - |
| Belden | Hirschmann Rsb20-0800M2M2Taabe | - |
| Belden | Hirschmann Rsb20-0800S2S2Saab | - |
| Belden | Hirschmann Rsb20-0800S2S2Saabe | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103340Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01MitigationThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/103340Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2018-5465?
CVE-2018-5465 is a vulnerability with a CVSS score of 8.8 (HIGH). A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface...
How severe is CVE-2018-5465?
CVE-2018-5465 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5465?
Check the references section above for vendor advisories and patch information. Affected products include: Belden Hirschmann Rs20-0900Mmm2Tdau, Belden Hirschmann Rs20-0900Nnm4Tdau, Belden Hirschmann Rs20-0900Vvm2Tdau, Belden Hirschmann Rs20-1600L2L2Sdau, Belden Hirschmann Rs20-1600L2M2Sdau.