← Back to CVE List

CVE-2023-35794

Published: 2023-10-27T21:15Z
Last Modified: 2024-11-21T08:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt