Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 3.5
affected
Description
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
Problem types
CWE-613 Insufficient Session Expiration
Product status
Any version before 3.5
References
www.2n.com/en-GB/download/cve_2025_59786_acom_3_5_v1pdf