Vulnerability vector:
- Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity (CVSSv3.1): 8.6 (high)
- Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
- Severity (CVSSv4.0): 8.8 (high)
Description:
The vulnerability was identified in Password Pusher versions prior to 1.48.0.
The application does not limit the storage time of the session identifier or credentials, or this time is excessively long. An attacker can reuse old credentials or session identifiers to log in as another user and gain unauthorized access to the application with the corresponding privileges.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 04.11.2024
Recommendations:
- Update to version or higher
Additional information: Positive Technologies