Leak of authentication sessions in secure logs
Vulnerability Description
The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27156
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.
References
More from Toshiba Tec Corporation
View All →Affected Vendor
Toshiba Tec Corporation
View all reports →