Navarino Infinity web interface up to version 2.2 is prone to session fixation attacks
Vulnerability Description
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-5385
Credits & Attribution
No credits recorded in the NVD database.
References
More from Navarino
View All →Affected Vendor
Navarino
View all reports →