Vulnerability Description
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scadabr | Scadabr | 1.12.4 |
Related Weaknesses (CWE)
References
- https://github.com/chiranjib2001/ScadaBR/blob/main/README.mdExploitMailing ListThird Party Advisory
FAQ
What is CVE-2025-70973?
CVE-2025-70973 is a vulnerability with a CVSS score of 4.8 (MEDIUM). ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentic...
How severe is CVE-2025-70973?
CVE-2025-70973 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-70973?
Check the references section above for vendor advisories and patch information. Affected products include: Scadabr Scadabr.