CVE-2023-24477

CVSS V2 None CVSS V3 None
Description
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
Overview
  • CVE ID
  • CVE-2023-24477
  • Assigner
  • prodsec@nozominetworks.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-08-09T08:15:09
  • Last Modified Date
  • 2023-08-15T16:09:11
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* 1 OR 22.6.2
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* 1 OR 22.6.2
References
Reference URL Reference Tags
https://security.nozominetworks.com/NN-2023:8-01 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-09-06 03:21:30 Added to TrackCVE
2023-09-06 03:21:33 Weakness Enumeration new