High8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

PT-2024-73: Unlimited session lifetime in Password Pusher

Error type:

  • CWE-613:Insufficient Session Expiration

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Severity (CVSSv3.1): 8.6 (high)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 8.8 (high)

Description:

The vulnerability was identified in Password Pusher versions prior to 1.48.0.

The application does not limit the storage time of the session identifier or credentials, or this time is excessively long. An attacker can reuse old credentials or session identifiers to log in as another user and gain unauthorized access to the application with the corresponding privileges.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 04.11.2024

Recommendations:

  • Update to version or higher

Additional information: Positive Technologies

Vendor:

Apnotic, LLC

Vulnerable product:

Password Pusher

Vulnerable versions:

< 1.48.0