// For flags

CVE-2024-11627

 

Severity Score

6.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

La vulnerabilidad de expiración de sesión insuficiente en Progress Sitefinity permite: fijación de sesión. Este problema afecta a Sitefinity: desde la versión 4.0 hasta la 14.4.8142, desde la versión 15.0.8200 hasta la 15.0.8229, desde la versión 15.1.8300 hasta la 15.1.8327, desde la versión 15.2.8400 hasta la 15.2.8421.

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-11-22 CVE Reserved
  • 2025-01-07 CVE Published
  • 2025-01-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-613: Insufficient Session Expiration
CAPEC
  • CAPEC-596: TCP RST Injection
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress
Search vendor "Progress"
Sitefinity
Search vendor "Progress" for product "Sitefinity"
>= 4.0.0 <= 14.4.8142
Search vendor "Progress" for product "Sitefinity" and version " >= 4.0.0 <= 14.4.8142"
en
Affected
Progress
Search vendor "Progress"
Sitefinity
Search vendor "Progress" for product "Sitefinity"
>= 15.0.8200 <= 15.0.8229
Search vendor "Progress" for product "Sitefinity" and version " >= 15.0.8200 <= 15.0.8229"
en
Affected
Progress
Search vendor "Progress"
Sitefinity
Search vendor "Progress" for product "Sitefinity"
>= 15.1.8300 <= 15.1.8327
Search vendor "Progress" for product "Sitefinity" and version " >= 15.1.8300 <= 15.1.8327"
en
Affected
Progress
Search vendor "Progress"
Sitefinity
Search vendor "Progress" for product "Sitefinity"
>= 15.2.8400 <= 15.2.8421
Search vendor "Progress" for product "Sitefinity" and version " >= 15.2.8400 <= 15.2.8421"
en
Affected