CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It may be remotely exploitable.
CVE
CVE-2008-1396
Severity
MEDIUM
CVSS
4.3
EPSS
1.13%
Original NVD Description
Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.