PT-2023-6853 · Moxa · Moxa Pt-G503 Series
Published
2023-09-18
·
Updated
2023-11-09
·
CVE-2023-5035
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moxa PT-G503 Series firmware versions prior to v5.2
Description
The issue is related to the absence of the
secure flag in session cookies, which could allow a remote attacker to gain unauthorized access to protected information. This may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.Recommendations
For Moxa PT-G503 Series firmware versions prior to v5.2, update to version v5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies in HTTPS sessions to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Pt-G503 Series