Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-12520

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.077
EPSS Ranking 91.5%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2018-12520
  • Ntop » Ntopng » Version: 3.4
    cpe:2.3:a:ntop:ntopng:3.4


Contact Us

Shodan ® - All rights reserved