CVE-2023-2876

Severity
6.1MEDIUM
EPSS
0.3%
top 51.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages6 packages

NVDabb/rex640_pcl1_firmware1.0.01.0.8
NVDabb/rex640_pcl2_firmware1.0.01.1.4
NVDabb/rex640_pcl3_firmware1.0.01.2.1
CVEListV5abb/rex640_pcl11.0;01.0.8
CVEListV5abb/rex640_pcl21.0;01.1.4

🔴Vulnerability Details

2
GHSA
GHSA-xxww-73xw-x3fj: Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (fir2023-06-13
CVEList
Session cookie exposure for client side script2023-06-13
CVE-2023-2876 (MEDIUM CVSS 6.1) | Sensitive Cookie Without 'HttpOnly' | cvebase.io