Loading HuntDB...

GHSA-xqww-5c9g-v62q

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To successfully achieve this, the attacker also needs to spoof both the IP address and MAC address of the originating host which is typical of a session-based attack.

Related CVEs

Key Information

GHSA ID
GHSA-xqww-5c9g-v62q
Published
September 13, 2024 6:31 PM
Last Modified
September 13, 2024 6:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.