CVE-2001-1534
published 2001-12-31CVE-2001-1534: mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.70%
49.5th percentile
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 1.3.11 – 1.3.20 | — |
| debian | apache2 | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp27-vhqc-jqvp: mod_usertrack in Apache 1
ghsa_unreviewed·2022-04-30
CVE-2001-1534 [LOW] CWE-384 GHSA-gp27-vhqc-jqvp: mod_usertrack in Apache 1
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
OSV
CVE-2001-1534: mod_usertrack in Apache 1
osv·2001-12-31·CVSS 2.1
CVE-2001-1534 [LOW] CVE-2001-1534: mod_usertrack in Apache 1
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
Debian
CVE-2001-1534: apache2 - mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predi...
vendor_debian·2001·CVSS 2.1
CVE-2001-1534 [LOW] CVE-2001-1534: apache2 - mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predi...
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Red Hat
CVE-2001-1534: mod_usertrack in Apache 1
vendor_redhat·CVSS 2.1
CVE-2001-1534 [LOW] CVE-2001-1534: mod_usertrack in Apache 1
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
Statement: This is not a security issue. The mod_usertrack cookies are not designed to be used for authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CAPEC
Session Credential Falsification through Prediction
mitre_capec
[HIGH] Session Credential Falsification through Prediction
CAPEC-59: Session Credential Falsification through Prediction
This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.
Execution Flow:
Step 1 [Explore]: [Find Session IDs] The attacker interacts with the target host and finds that session IDs are used to authenticate users.
Technique: An attacker makes many anonymous connections and records the session IDs assigned.
Technique: An attacker makes authorized connections and records the session tokens or credentials issued.
Step 2 [Explore]: [Characterize IDs] The attacker studies the characteristics of the session ID (size, format, etc.). As a results the attacker finds that legitimate session IDs are predictable.
Tech
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.htmlhttp://www.iss.net/security_center/static/7494.phphttp://www.securityfocus.com/bid/3521http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.htmlhttp://www.iss.net/security_center/static/7494.phphttp://www.securityfocus.com/bid/3521
2001-12-31
Published