CVE-2018-12520
Estado: ModificadaAlta (8.1)—
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 11%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-335
Referencias
- http://seclists.org/fulldisclosure/2018/Jul/14
- https://gist.github.com/Psychotropos/3e8c047cada9b1fb716e6a014a428b7f
- https://github.com/ntop/ntopng/commit/30610bda60cbfc058f90a1c0a17d0e8f4516221a
- https://www.exploit-db.com/exploits/44973/
- http://seclists.org/fulldisclosure/2018/Jul/14
- https://gist.github.com/Psychotropos/3e8c047cada9b1fb716e6a014a428b7f
- https://github.com/ntop/ntopng/commit/30610bda60cbfc058f90a1c0a17d0e8f4516221a
- https://www.exploit-db.com/exploits/44973/
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-12520",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-07-05T20:29:00.527",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2018/Jul/14",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/Psychotropos/3e8c047cada9b1fb716e6a014a428b7f",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ntop/ntopng/commit/30610bda60cbfc058f90a1c0a17d0e8f4516221a",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/44973/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2018/Jul/14",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gist.github.com/Psychotropos/3e8c047cada9b1fb716e6a014a428b7f",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ntop/ntopng/commit/30610bda60cbfc058f90a1c0a17d0e8f4516221a",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/44973/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-335"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en ntopng, en versiones 3.4 anteriores a la 3.4.180617. El PRNG implicado en la generación de ID de sesión no se propaga al iniciar el programa. Esto resulta en que se asignan ID de sesión deterministas para las sesiones activas de usuario. Un atacante con conocimientos del sistema operativo y biblioteca estándar en uso por parte del host que ejecuta el servicio y el nombre de usuario del usuario cuya sesión está en el punto de mira puede abusar de la generación determinista de números aleatorios para secuestrar la sesión del usuario y escalando su acceso."
}
],
"lastModified": "2026-06-17T01:37:53.913",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4430DA75-F986-4B4E-9163-789C6269C328",
"versionEndExcluding": "3.4.180617",
"versionStartIncluding": "3.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}