CVE-2020-29667: Lanatmservice m3 ATM Monitoring System
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
Affected products
- Lanatmservice m3 ATM Monitoring System: version 6.1.0 only
Published 2020-12-10. Last modified 2026-06-17.