An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.
References
Link | Resource |
---|---|
https://blog.kscsc.online/cves/202335794/md.html | |
https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking | Exploit Third Party Advisory |
https://www.cassianetworks.com/products/iot-access-controller/ | Product |
Configurations
History
No history.
Information
Published : 2023-10-27 21:15
Updated : 2024-01-29 21:15
NVD link : CVE-2023-35794
Mitre link : CVE-2023-35794
CVE.ORG link : CVE-2023-35794
JSON object : View
Products Affected
cassianetworks
- access_controller
CWE
CWE-287
Improper Authentication