HIGH🇵🇱 Wersja polska

CVE-2018-12520

CVSS 8.1v3.1pub. 2018-07-05upd. 2024-11-21

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Ntop Ntopng

    APP
    Ntop
    3.4 – 3.4.180617 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-38968CRITICAL9.8PL ✓same product

ntopng: przewidywalne identyfikatory sesji umożliwiające Session Hijacking

CVE-2017-7458HIGH7.5same product

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to...

CVE-2017-7459HIGH7.5same product

ntopng before 3.0 allows HTTP Response Splitting.

CVE-2017-5473HIGH8.8same product

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the au...

CVE-2017-7416MEDIUM6.1same product

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.