ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
References
| Link | Resource |
|---|---|
| https://github.com/chiranjib2001/ScadaBR/blob/main/README.md | Exploit Mailing List Third Party Advisory |
Configurations
History
07 Apr 2026, 16:04
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:scadabr:scadabr:1.12.4:*:*:*:*:*:*:* | |
| References | () https://github.com/chiranjib2001/ScadaBR/blob/main/README.md - Exploit, Mailing List, Third Party Advisory | |
| First Time |
Scadabr scadabr
Scadabr |
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
| CWE | CWE-384 |
09 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-09 21:16
Updated : 2026-04-07 16:04
NVD link : CVE-2025-70973
Mitre link : CVE-2025-70973
CVE.ORG link : CVE-2025-70973
JSON object : View
Products Affected
scadabr
- scadabr
CWE
CWE-384
Session Fixation
