6.8
CVSSv2

CVE-2017-14007

Published: 17/10/2017 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.6 | Impact Score: 3.4 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An Insufficient Session Expiration issue exists in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an malicious user to reuse an old session for authorization.

Vulnerable Product Search on Vulmon Subscribe to Product

prominent multiflex_m10a_controller_firmware