CVE-2013-4732

The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network.  NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
digital_alert_systemsdasdec_eas
𝑥
≤ 2.0-2
digital_alert_systemsdasdec_eas
2.0-0
digital_alert_systemsdasdec_eas
2.0-1
monroe_electronicsr189_one-net_eas
𝑥
≤ 2.0-2
monroe_electronicsr189_one-net_eas
2.0-0
monroe_electronicsr189_one-net_eas
2.0-1
𝑥
= Vulnerable software versions
Common Weakness Enumeration