cbcvebase.
CVE-2014-9386
published 2014-12-15

CVE-2014-9386: Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging…

PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.05%
78.8th percentile
Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.

Affected

16 ranges
VendorProductVersion rangeFixed in
zenosszenoss_core<= 4.2.5
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
zenosszenoss_core
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.

CVE-2014-9386 — Zenoss Core vulnerability | cvebase