PT-2023-25348 · Unknown · Siren Investigate

CVE-2023-35857

·

Published

2023-06-19

·

Updated

2023-06-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Siren Investigate versions prior to 13.2.2
Description The issue concerns session keys remaining active even after a user logs out. This could potentially allow unauthorized access to user sessions.
Recommendations For versions prior to 13.2.2, update to version 13.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources or implementing additional authentication measures to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-35857

Affected Products

Siren Investigate