ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
References
| Link | Resource |
|---|---|
| https://github.com/chiranjib2001/ScadaBR/blob/main/README.md | Exploit Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-09 21:16
Updated : 2026-06-17 10:03
NVD link : CVE-2025-70973
Mitre link : CVE-2025-70973
CVE.ORG link : CVE-2025-70973
JSON object : View
Products Affected
scadabr
- scadabr
CWE
CWE-384
Session Fixation
