CVE-2025-24502

An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Feb 2025, 05:15

Type Values Removed Values Added
Summary
  • (es) Una validación de sesión incorrecta permite que un atacante no autenticado haga que ciertas notificaciones de solicitud se ejecuten en el contexto de un usuario incorrecto falsificando la dirección IP del cliente.
References
  • {'url': 'https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678', 'source': 'secure@symantec.com'}
  • () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25362 -

30 Jan 2025, 20:15

Type Values Removed Values Added
CWE CWE-384

30 Jan 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 19:15

Updated : 2025-02-05 05:15


NVD link : CVE-2025-24502

Mitre link : CVE-2025-24502

CVE.ORG link : CVE-2025-24502


JSON object : View

Products Affected

No product.

CWE
CWE-384

Session Fixation