« Volver al listado

CVE-2024-28144

Estado: AplazadaMedia (5.5)—

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28144",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28144",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-13T16:30:17.378452Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "affectedData": [
        {
          "vendor": "Image Access GmbH",
          "product": "Scan2Net",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.42B",
                  "status": "unknown"
                }
              ],
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "7.42B"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-12-12T14:15:22.330",
  "references": [
    {
      "url": "https://r.sec-consult.com/imageaccess",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "https://www.imageaccess.de/?page=SupportPortal&lang=en",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Dec/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user."
    },
    {
      "lang": "es",
      "value": "Un atacante que pueda falsificar la dirección IP y el User-Agent de un usuario conectado puede tomar el control de la sesión debido a fallas en la administración de sesiones desarrollada por él mismo. Si dos usuarios acceden a la interfaz web desde la misma IP, inician sesión como el otro usuario."
    }
  ],
  "lastModified": "2026-06-17T07:21:04.670",
  "sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}