Loading
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.
Use CWE-384, Scadabr vendor hub and Scadabr product page to widen CVE-2025-70973 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-26828, CVE-2021-26829 and CVE-2019-16344 for nearby disclosures in the same product family.