AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-28395

HIGH · CVSS 8.3 EPSS 0.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-03-28 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-28395
Severity
HIGH
CVSS
8.3
EPSS
0.65%

Original NVD Description

Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.