CVE-2018-16495: High severity versa networks versa operating system vulnerability
In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16495?
CVE-2018-16495 is classified as a high severity vulnerability due to the potential for session hijacking.
How do I fix CVE-2018-16495?
To address CVE-2018-16495, ensure that a new session identifier is issued after user authentication.
What type of attacks can CVE-2018-16495 enable?
CVE-2018-16495 can enable session fixation attacks, allowing an attacker to impersonate a legitimate user.
Which software is affected by CVE-2018-16495?
CVE-2018-16495 affects multiple versions of Versa Networks Versa Operating System up to 20.2.2 and specific 21.1.x versions.
Is CVE-2018-16495 reversible once exploited?
Once exploited, the effects of CVE-2018-16495 may not be easily reversible without user intervention or re-authentication.