Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.
| Software | From | Fixed in |
|---|---|---|
| lucent / vitalevent | 8.0 | 8.0.x |
| lucent / vitalsuite | 8.0 | 8.0.x |
| lucent / vitalsuite | 8.2 | 8.2.x |
| lucent / vitalnet | 8.0 | 8.0.x |
| lucent / vitalsuite | 8.1 | 8.1.x |
| lucent / vitalanalysis | 8.0 | 8.0.x |
| lucent / vitalhelp | 8.2 | 8.2.x |
| lucent / vitalanalysis | 8.2 | 8.2.x |
| lucent / vitalnet | 8.1 | 8.1.x |
| lucent / vitalhelp | 8.0 | 8.0.x |
| lucent / vitalevent | 8.2 | 8.2.x |
| lucent / vitalhelp | 8.1 | 8.1.x |
| lucent / vitalanalysis | 8.1 | 8.1.x |
| lucent / vitalnet | 8.2 | 8.2.x |
| lucent / vitalevent | 8.1 | 8.1.x |