Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43149 | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 19 Mar 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Fri, 10 Jan 2025 03:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-384 | |
| Metrics |
cvssV3_1
|
Fri, 01 Nov 2024 05:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied. |
Thu, 31 Oct 2024 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netadmin
Netadmin netadmin |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:netadmin:netadmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netadmin
Netadmin netadmin |
|
| Metrics |
cvssV3_1
|
Wed, 30 Oct 2024 02:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T18:37:32.449Z
Reserved: 2024-10-10T00:00:00.000Z
Link: CVE-2024-48955
Updated: 2024-10-30T15:10:36.718Z
Status : Awaiting Analysis
Published: 2024-10-29T18:15:05.690
Modified: 2025-03-18T19:15:45.317
Link: CVE-2024-48955
No data.
OpenCVE Enrichment
No data.
EUVD