CVE-2018-10240

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
16/05/2018
Last modified:
25/06/2018

Description

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* 15.1.6 (including)