CVE-2017-14007 Information
Feb 14, 2021
cve
Description
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user’s session is available for an extended period beyond the last activity allowing an attacker to reuse an old session for authorization.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
http://www.securityfocus.com/bid/101259 https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.6
Share on: