CVE-2025-70973

ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
References
Link Resource
https://github.com/chiranjib2001/ScadaBR/blob/main/README.md Exploit Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:scadabr:scadabr:1.12.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-09 21:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70973

Mitre link : CVE-2025-70973

CVE.ORG link : CVE-2025-70973


JSON object : View

Products Affected

scadabr

  • scadabr
CWE
CWE-384

Session Fixation