An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.
References
Link | Resource |
---|---|
https://blog.kscsc.online/cves/202335794/md.html | |
https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking | Exploit Third Party Advisory |
https://www.cassianetworks.com/products/iot-access-controller/ | Product |
https://blog.kscsc.online/cves/202335794/md.html | |
https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking | Exploit Third Party Advisory |
https://www.cassianetworks.com/products/iot-access-controller/ | Product |
Configurations
History
21 Nov 2024, 08:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.kscsc.online/cves/202335794/md.html - | |
References | () https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking - Exploit, Third Party Advisory | |
References | () https://www.cassianetworks.com/products/iot-access-controller/ - Product |
29 Jan 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Nov 2023, 01:20
Type | Values Removed | Values Added |
---|---|---|
First Time |
Cassianetworks
Cassianetworks access Controller |
|
CPE | cpe:2.3:a:cassianetworks:access_controller:2.1.1.2303271039:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | (MISC) https://www.cassianetworks.com/products/iot-access-controller/ - Product | |
References | (MISC) https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking - Exploit, Third Party Advisory | |
CWE | CWE-287 |
27 Oct 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-27 21:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35794
Mitre link : CVE-2023-35794
CVE.ORG link : CVE-2023-35794
JSON object : View
Products Affected
cassianetworks
- access_controller
CWE
CWE-287
Improper Authentication