Advisory ID | NN-2023:8-01 |
---|---|
Topic | Session Fixation in Guardian/CMC before 22.6.2 |
CWE Impact | CWE-384: Session Fixation |
Issue date | 2023-08-09 |
Affects | Guardian, CMC < v22.6.2 |
CVE Name(s) | CVE-2023-24477 |
CVSS Details | CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS Score | 5.4 (CVSS v4.0) 7.0 (CVSS v3.1) |
CVE Risk Level | Medium (CVSS v4.0) High (CVSS v3.1) |
Risk Level for Nozomi customers | Medium |
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
Unauthorized access.
Guardian, CMC < v22.6.2
Adopt best practices that include closing the browser after a logout.
Upgrade to v22.6.2, v23.0.0 or later.
We thank the following parties for their efforts: