← לוח פגיעויות

CVE-2026-66372

בינונית 6.8

תיאור (מקור, אנגלית)

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

מדדים

CVSS 3.1
6.8 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 4.0
7.6 (HIGH) מקור הציון: CNA CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-19/9/2026
CWE
CWE-337

קישורים