peter bassill · operator
$ cve CVE-2014-1219 JSON

CVE-2014-1219 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS4.6% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2014-02-14
Last modified2026-06-17

Affected (1)

VendorProduct
broadcom2e web option

Public exploits

SourceTitleDate
exploit-dbCA 2E Web Option 8.1.2 - Authentication Bypass2014-02-13

References

→ the Explorer  ·  watch your stack  ·  NVD