PT-2023-6853 · Moxa · Moxa Pt-G503 Series
CVE-2023-5035
·
Publicado
2023-09-18
·
Atualizado
2023-11-09
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moxa PT-G503 Series firmware versions prior to v5.2
Description
The issue is related to the absence of the
secure flag in session cookies, which could allow a remote attacker to gain unauthorized access to protected information. This may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.Recommendations
For Moxa PT-G503 Series firmware versions prior to v5.2, update to version v5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies in HTTPS sessions to minimize the risk of exploitation.
Correção
Cleartext Transmission of Sensitive Information
Exposure of Resource to Wrong Sphere
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Moxa Pt-G503 Series