Back to search
CVE-2009-4509
Published: Apr 13, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/secure.php and (2) tandberg/web/user/lib/secure.php, which makes it easier for remote attackers to bypass authentication, and execute arbitrary code by loading a custom software update, via a crafted "Cookie: tandberg_login=" HTTP header.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.vsecurity.com/resources/advisory/20100409-1
x_refsource_MISC
39275
third-party-advisory
x_refsource_SECUNIA
20100410 CVE-2009-4509: TANDBERG VCS Authentication Bypass
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now