CVE-2024-39275: Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive Information
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39275?
CVE-2024-39275 has a high severity rating due to the risks of unauthorized access through session cookie exploitation.
How do I fix CVE-2024-39275?
To mitigate CVE-2024-39275, ensure server-side validation of session cookies and implement proper session management practices.
Who is affected by CVE-2024-39275?
CVE-2024-39275 affects users of Advantech ADAM-5630 devices running firmware versions prior to 2.5.2.
What is the nature of the vulnerability in CVE-2024-39275?
CVE-2024-39275 allows unauthorized users to forge requests using valid cookies after a session has been closed.
Is there a patch available for CVE-2024-39275?
Yes, Advantech has released a firmware update to address the vulnerabilities outlined in CVE-2024-39275.