CVE-2022-40630

MEDIUM

Tacitine Firewall <22.20.1 - Session Fixation

Title source: llm
STIX 2.1

Description

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (2)
tacitine/en6200-prime_quad-100_firmware 19.1.1 - 22.21.2
tacitine/en6200-prime_quad-35_firmware 19.1.1 - 22.21.2
Published Sep 23, 2022
Tracked Since Feb 18, 2026