Skip to main content

Incorrect Implementation of Authentication Algorithm

CVE-2024-8314

Severity Medium
Score 5.5/10

Summary

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

  • LOW
  • NETWORK
  • PASSIVE
  • LOW

CWE-303 - Incorrect Implementation of Authentication Algorithm

The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

References

Advisory Timeline

  • Published