CVE-2013-4732
Severity CVSS v4.0:
Pending analysis
Type:
CWE-255
Credentials Management
Publication date:
30/06/2013
Last modified:
11/04/2025
Description
The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:h:digital_alert_systems:dasdec_eas:*:*:*:*:*:*:*:* | 2.0-2 (including) | |
| cpe:2.3:h:digital_alert_systems:dasdec_eas:2.0-0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digital_alert_systems:dasdec_eas:2.0-1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:monroe_electronics:r189_one-net_eas:*:*:*:*:*:*:*:* | 2.0-2 (including) | |
| cpe:2.3:h:monroe_electronics:r189_one-net_eas:2.0-0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:monroe_electronics:r189_one-net_eas:2.0-1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf
- http://www.kb.cert.org/vuls/id/662676
- http://www.kb.cert.org/vuls/id/AAMN-98MU7H
- http://www.kb.cert.org/vuls/id/AAMN-98MUK2
- http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf
- http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf
- http://www.kb.cert.org/vuls/id/662676
- http://www.kb.cert.org/vuls/id/AAMN-98MU7H
- http://www.kb.cert.org/vuls/id/AAMN-98MUK2
- http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf



