Unrated severityNVD Advisory· Published Feb 28, 2004· Updated Jun 16, 2026
CVE-2004-0944
CVE-2004-0944
Description
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.
Affected products
1- Range: <4.2.2.11
Patches
Vulnerability mechanics
References
3- www.mitel.com/DocControllernvdPatchVendor Advisory
- www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdfnvdPatchVendor Advisory
- www.corsaire.com/advisories/c040817-002.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.