Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
Description
The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.
Problem types
CWE-613 Insufficient Session Expiration
Product status
Any version
Credits
Tomer Goldschmidt and Noam Moshe of Claroty Team82
References
www.cisa.gov/news-events/ics-advisories/icsa-25-175-07