Showing 1 vulnerability on this page for Artica Proxy

Signals CISA KEV Ransomware Nuclei
articatech vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Artica Proxy 4.50 Session Fixation via fw.login.php

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the attacker gains a fully authenticated administrative session on port 9000.

CWE-94Jul 28, 2026
CVSS7.5v4.0EPSS0.316%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX