Vulnerability Description
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/imageaccess
- https://www.imageaccess.de/?page=SupportPortal&lang=en
- http://seclists.org/fulldisclosure/2024/Dec/2
FAQ
What is CVE-2024-28144?
CVE-2024-28144 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interfac...
How severe is CVE-2024-28144?
CVE-2024-28144 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28144?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.