PoC Index

CVE-2023-35794

HIGH 8.8EPSS 0.9%

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.94% chance of exploitation in the next 30 days, 59th percentile
Published
2023-10-27
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related