ZeroHour

CVE-2018-1148

CVSS 3.0
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

Vendors
tenable
Products
nessus
Weakness
CWE-384
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.