[CVE-2018-10240] SolarWinds Serv-U Managed File Transfer – Insufficient Session ID Entropy
bishopfox.com | advisory | CVE-2018-10240 | #brute-force | #solarwinds | #session-hijacking | #serv-u | #vulnerability-advisory | #cve-2018-10240
Summary
SolarWinds Serv-U MFT 15.1.6.25 issues low-entropy integer session tokens usable in URLs; a brute-forced value hijacks sessions after only 4,780 guesses (CVE-2018-10240).
- Published
- Collected
Skip to content