CVE-2024-47945 is a critical session hijacking vulnerability affecting Rittal CMC III Processing Units and IoT Interface devices. The flaw stems from insufficient entropy in session ID generation, using a predictable rand() function without proper initialization, leading to only 32,768 possible session IDs per user. This allows attackers to pre-generate valid session IDs, granting unauthorized access to user sessions with a CVSS score of 9.8 (Critical). The attack vector is network-based with low complexity, requiring no privileges or user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. While there is one community mention, there is no evidence of active exploitation, public exploit code, or media coverage at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.21.00.2CPE matchmatch criteria | cpe:2.3:o:rittal:iot_interface_firmware:*:*:*:*:*:*:*:* | ||
< 6.21.00.2CPE matchmatch criteria | cpe:2.3:o:rittal:cmc_iii_processing_units_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.