CVE-2023-49259
HIGHDescription
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.
Is your site exposed to CVE-2023-49259?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hongdian | h8951-4g-esp_firmware |
| hongdian | h8951-4g-esp |
References
Frequently Asked Questions
What is CVE-2023-49259? +
How severe is CVE-2023-49259? +
What products are affected by CVE-2023-49259? +
How do I check if I'm vulnerable to CVE-2023-49259? +
Related Vulnerabilities
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp …
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of …
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible …
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from …
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers …
A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote …