CVE-2021-39290
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.
Published:Aug 23, 2021
Last Modified:Nov 21, 2024
EPS:Aug 23, 2021
EPSS Score:0.0051
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Netmodule
Product
Nb1600
Netmodule
Nb1600
Vendor
Netmodule
Product
Nb1601
Netmodule
Nb1601
Vendor
Netmodule
Product
Nb1800
Netmodule
Nb1800
Vendor
Netmodule
Product
Nb1810
Netmodule
Nb1810
Vendor
Netmodule
Product
Nb2700
Netmodule
Nb2700
Vendor
Netmodule
Product
Nb2710
Netmodule
Nb2710
Vendor
Netmodule
Product
Nb2800
Netmodule
Nb2800
Vendor
Netmodule
Product
Nb2810
Netmodule
Nb2810
Vendor
Netmodule
Product
Nb3700
Netmodule
Nb3700
Vendor
Netmodule
Product
Nb3701
Netmodule
Nb3701
Vendor
Netmodule
Product
Nb3710
Netmodule
Nb3710
Vendor
Netmodule
Product
Nb3711
Netmodule
Nb3711
Vendor
Netmodule
Product
Nb3720
Netmodule
Nb3720
Vendor
Netmodule
Product
Nb3800
Netmodule
Nb3800
Vendor
Netmodule
Product
Nb800
Netmodule
Nb800
Vendor
Netmodule
Product
Netmodule Router Software
Netmodule
Netmodule Router Software
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
