CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 10.0. It may be remotely exploitable.
CVE
CVE-2013-4732
Severity
HIGH
CVSS
10
EPSS
3.04%
Original NVD Description
The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.