Vulnerability Description
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cassianetworks | Access Controller | 2.1.1.2303271039 |
Related Weaknesses (CWE)
References
- https://blog.kscsc.online/cves/202335794/md.html
- https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-HijackingExploitThird Party Advisory
- https://www.cassianetworks.com/products/iot-access-controller/Product
- https://blog.kscsc.online/cves/202335794/md.html
- https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-HijackingExploitThird Party Advisory
- https://www.cassianetworks.com/products/iot-access-controller/Product
FAQ
What is CVE-2023-35794?
CVE-2023-35794 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie v...
How severe is CVE-2023-35794?
CVE-2023-35794 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-35794?
Check the references section above for vendor advisories and patch information. Affected products include: Cassianetworks Access Controller.