Alcatel-Lucent OmniSwitch Web Interface Weak Session ID

Discussion in 'News Aggregator' started by Packet Storm, 10 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    During a penetration test, RedTeam Pentesting discovered a vulnerability in the management web interface of an Alcatel-Lucent OmniSwitch 6450. This interface uses easily guessable session IDs, which allows attackers to authenticate as a currently logged-in user and perform administrative tasks.

    Continue reading...
     

Share This Page

Loading...