Security Advisory

CVE-2024-28144

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-12-12 13:24:16
Last updated 2025-11-03 21:54:29
Assigner SEC-VLab
CVSS score not scored
State PUBLISHED

Description

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.