Security Advisory

CVE-2024-39275

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-09-27 17:38:20
Last updated 2024-09-27 18:14:05
Assigner icscert
CVSS score 8.0
State PUBLISHED

Description

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.