First published: Fri Mar 28 2014(Updated: )
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC VPLEX GeoSynchrony | =4.0 | |
Dell EMC VPLEX GeoSynchrony | =5.0 | |
Dell EMC VPLEX GeoSynchrony | =5.1 | |
Dell EMC VPLEX GeoSynchrony | =5.2 | |
Dell EMC VPLEX GeoSynchrony | =5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0635 is considered a medium severity vulnerability due to its potential to allow session hijacking.
To fix CVE-2014-0635, upgrade EMC VPLEX GeoSynchrony to version 5.3 or later.
CVE-2014-0635 affects EMC VPLEX GeoSynchrony versions 4.x and 5.x prior to 5.3.
CVE-2014-0635 is a session fixation vulnerability.
Yes, CVE-2014-0635 can be exploited remotely, allowing attackers to hijack web sessions.