CVE-2017-14013

Published Oct 17, 2017

Last updated 5 years ago

Overview

Description
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. This may allow an attacker to bypass protection mechanisms, gain privileges, or assume the identity of an authenticated user.
Source
ics-cert@hq.dhs.gov
NVD status
Modified

Risk scores

CVSS 3.0

Type
Primary
Base score
5.6
Impact score
3.4
Exploitability score
2.2
Vector string
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.4
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-669
ics-cert@hq.dhs.gov
CWE-602

Social media

Hype score
Not currently trending

Configurations