Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
Cisco Prime LAN Management Solution 安全漏洞
Vulnerability Description
Cisco Prime LAN Management Solution(LMS)是美国思科(Cisco)公司的一套基于局域网的网络管理解决方案。该解决方案可对网络进行配置、管理、监控和维护。 Cisco Prime LMS 4.2(5)版本中的网络功能存在会话固定漏洞,该漏洞源于程序在身份验证会话中重新使用了之前的身份验证会话令牌。远程攻击者可利用该漏洞劫持用户的会话。
CVSS Information
N/A
Vulnerability Type
N/A