PT-2023-6852 · Unknown · Pt-G503 Series

Published

2023-08-08

·

Updated

2023-11-09

·

CVE-2023-4217

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PT-G503 Series versions prior to v5.2
Description A vulnerability has been identified where the session cookies attribute is not set properly in the affected application, potentially exposing user session data to unauthorized access and manipulation. The vulnerability is related to the use of cookies for storing confidential information without the HttpOnly flag.
Recommendations For PT-G503 Series versions prior to v5.2, consider updating to version v5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to session cookies to minimize the risk of exploitation. Avoid using the session cookies attribute in the affected application until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2023-07861
CVE-2023-4217

Affected Products

Pt-G503 Series