← back
CVE-2017-5141

CVE-2017-5141

EPSS 1.1%
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION).

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →