CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2009-4509

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1950%
EPSS Percentile36.19th
Published2010年4月13日
Last Modified2026年4月29日

Vulnerability Description

The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/secure.php and (2) tandberg/web/user/lib/secure.php, which makes it easier for remote attackers to bypass authentication, and execute arbitrary code by loading a custom software update, via a crafted "Cookie: tandberg_login=" HTTP header.

Affected Platforms (CPE)

📦
Vsecurity

Tandberg Video Communication Server

<= x4.2.1
📦
Vsecurity

Tandberg Video Communication Server

= x1.0.0
📦
Vsecurity

Tandberg Video Communication Server

= x1.1.0
📦
Vsecurity

Tandberg Video Communication Server

= x1.2.0
📦
Vsecurity

Tandberg Video Communication Server

= x2.0.0
📦
Vsecurity

Tandberg Video Communication Server

= x2.1.0
📦
Vsecurity

Tandberg Video Communication Server

= x3.0.0
📦
Vsecurity

Tandberg Video Communication Server

= x3.1.0
📦
Vsecurity

Tandberg Video Communication Server

= x4.1.0
📦
Vsecurity

Tandberg Video Communication Server

= x4.2.0

References & Advisories

相關漏洞威脅