216.73.217.22

CVE-2025-70973

· Published 09/03/2026 21:16 · Modified 10/03/2026 18:18

Labels: CVE-2025-70973 2026-03-09CVE-2025-70973CWE-384[email protected]

Essential information

Published
09/03/2026 21:16
Modified
10/03/2026 18:18
Author
Creator
CVSS
4.8 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
scadabr / scadabr cpe:2.3:a:scadabr:scadabr:1.12.4:*:*:*:*:*:*:*

References