CVE-2016-7090
published 2016-09-29CVE-2016-7090: The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https…
PriorityP418medium4CVSS 3.0
AVNACHPRNUINSCCLINAN
EPSS
1.90%
77.2th percentile
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | scalance_m-800_firmware | <= 4.01 | — |
| siemens | scalance_s615_firmware | <= 4.01 | — |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwq7-h765-5h5f: The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4
ghsa_unreviewed·2022-05-17
CVE-2016-7090 [MEDIUM] CWE-200 GHSA-mwq7-h765-5h5f: The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CISA ICS
Siemens SCALANCE M-800/S615 Web Vulnerability
cisa_ics·2018-08-22
Siemens SCALANCE M-800/S615 Web Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE M-800/S615 Web Vulnerability
Last RevisedAugust 22, 2018
Alert CodeICSA-16-271-01
## OVERVIEW
Siemens has identified a web security vulnerability in Siemen’s SCALANCE M-800 and S615 modules. This vulnerability was reported directly to Siemens by Alexander Van Maele and Tijl Deneut from HOWEST. Siemens has produced a new firmware version to mitigate this vulnerability.
## AFFECTED PRODUCTS
Siemens reports that the vulnerability affects the following products:
- SCALANCE M-800/S615: All versions before V4.02
## IMPACT
Exploitation of this vulnerability could
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93115http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-342135.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-271-01http://www.securityfocus.com/bid/93115http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-342135.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-16-271-01
2016-09-29
Published