CVE-2023-24477: Session Fixation in Guardian/CMC before 22.6.2
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24477.
What is the severity of CVE-2023-24477?
The severity of CVE-2023-24477 is high.
How does CVE-2023-24477 impact Nozominetworks Cmc?
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout, allowing an authenticated local attacker to gain access to the original user's session.
How can I fix CVE-2023-24477?
To fix CVE-2023-24477, upgrade Guardian/CMC to version 22.6.2 or newer.
Where can I find more information about CVE-2023-24477?
More information about CVE-2023-24477 can be found at the following link: [CVE-2023-24477](https://security.nozominetworks.com/NN-2023:8-01).