CVE-2024-13967 PUBLISHED

ession-Management Failure

Assigner: ABB
Reserved: 04.06.2025 Published: 04.06.2025 Updated: 04.06.2025

This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT.

This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.9.8.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor ABB
Product EIBPORT V3 KNX
Versions Default: unaffected
  • affected from 0 to 3.9.8 (incl.)
Vendor ABB
Product EIBPORT V3 KNX GSM
Versions Default: unaffected
  • affected from 0 to 3.9.8 (incl.)

Credits

  • Psytester for describing the findings and helping to verify the resolving implementation finder
  • Frank van den Hurk for working with us to help protect customers finder

References

Problem Types

  • CWE-384 Session Fixation CWE