CVE-2025-70973
ScadaBR 1.12.4 - Session Fixation
Title source: llmDescription
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
Scores
Classification
Status
draft
Timeline
Published
Mar 09, 2026
Tracked Since
Mar 10, 2026