CVE-2021-29012
Summary
| CVE | CVE-2021-29012 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-02 13:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dmasoftlab | Dma Radius Manager | 4.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DMA Softlab Radius Manager 4.4.0 Session Management / Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| publications/cve-2021-29012 at main · 1d8/publications · GitHub | MISC | github.com | |
| DMA Softlab Radius Manager 4.1.6 download | SourceForge.net | MISC | sourceforge.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.