Description
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
Scores
CVSS v3
9.8
EPSS
0.0029
EPSS Percentile
52.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-311
CWE-200
CWE-522
CWE-338
CWE-732
Status
published
Products (1)
adremsoft/netcrunch
< 11.0.0.5282
Published
Dec 16, 2020
Tracked Since
Feb 18, 2026