CVE-2024-28144

MEDIUM

Session Management - SSRF

Title source: llm
STIX 2.1

Description

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (1)
Image Access GmbH/Scan2Net < 7.42B
Published Dec 12, 2024
Tracked Since Feb 18, 2026