Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
CVE-2020-29667 — Proof-of-concept exploit for CVE-2020-29667 targeting insufficient session expiration and a hardcoded cookie value in Lan ATMService M3 ATM Monitoring System 6.1.0, enabling remote control of ATM states. | Kitploit
Proof-of-concept exploit for CVE-2020-29667 targeting insufficient session expiration and a hardcoded cookie value in Lan ATMService M3 ATM Monitoring System 6.1.0, enabling remote control of ATM states.
Insufficient Session Expiration | Predefined Cookie Value
[Suggested description]
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system and operate remote ATM maschines current state, because of Insufficient Session Expiration and Predefined Cookie Value.
[Additional Information]
A letter was sent to the vendor about the vulnerability.