vendor:
Analog FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Session Hijacking
284
CWE
Product Name: Analog FM Transmitter
Affected Version From: 2.12 (EXC5000GX)
Affected Version To: 1.5.4 (EXC120GT)
Patch Exists: NO
Related CWE:
CPE: a:sielco:analog_fm_transmitter
Platforms Tested: lwIP/2.1.1, Web/3.0.3
2023
Sielco Analog FM Transmitter 2.12 – ‘id’ Cookie Brute Force Session Hijacking
The Cookie session ID 'id' is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication and manipulate the transmitter.
Mitigation:
Ensure that session IDs are of sufficient length and complexity to prevent brute force attacks.