CVE-2017-15304
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2017
Last modified:
20/04/2025
Description
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin password change.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:airtame:hdmi_dongle_firmware:*:b1:*:*:*:*:*:* | 2.3.3 (including) | |
cpe:2.3:h:airtame:hdmi_dongle:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page