CVE-2023-41089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
19/10/2023
Last modified:
25/10/2023

Description

<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the cookie header to generate "legitimate" requests.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dexma:dexgate:20130114:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools