Metrics
Affected Vendors & Products
Tue, 18 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
Thu, 09 Jan 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-384 | |
Metrics |
cvssV3_1
|
Thu, 31 Oct 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied. |
Wed, 30 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netadmin
Netadmin netadmin |
|
Weaknesses | CWE-384 | |
CPEs | cpe:2.3:a:netadmin:netadmin:*:*:*:*:*:*:*:* | |
Vendors & Products |
Netadmin
Netadmin netadmin |
|
Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T18:37:32.449Z
Reserved: 2024-10-10T00:00:00.000Z
Link: CVE-2024-48955

Updated: 2024-10-30T15:10:36.718Z

Status : Awaiting Analysis
Published: 2024-10-29T18:15:05.690
Modified: 2025-03-18T19:15:45.317
Link: CVE-2024-48955

No data.