CVE-2024-39275
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Sep 27, 2024
Updated: Oct 7, 2024
CWE ID 539
Summary
CVE-2024-39275 is a vulnerability affecting the Advantech ADAM-5630. This issue allows unauthorized attackers to bypass session termination and assume the privileges of an authenticated user. Cookies remain active after a session has been closed, enabling forged requests with valid cookies to gain unauthorized access. This security flaw poses a significant risk, as attackers can perform actions indistinguishable from those of the legitimate user.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.