CVE Feed

    Dashboard / CVE / CVE-2024-1623

    CVE-2024-1623

    Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details correctly.

    Published:Mar 14, 2024
    Last Modified:Jan 23, 2025
    EPS:Mar 14, 2024
    EPSS Score:0.0003
    CVSS Score:7.7

    Affected Products

    Vendor
    Sagemcom
    Product
    F\@st 3686
    Vendor
    Sagemcom
    Product
    F\@st 3686 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High