9.8
CVSSv3

CVE-2020-29667

Published: 10/12/2020 Updated: 14/12/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lanatmservice m3 atm monitoring system 6.1.0

Github Repositories

CVE-2020-29667 Insufficient Session Expiration | Predefined Cookie Value [Suggested description] In Lan ATMService M3 ATM Monitoring System 610, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system and operate remote ATM maschines current state, because of Insufficient Session Expiration and Predefined Coo