CVE-2023-2876
published 2023-06-13CVE-2023-2876: Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.29%
21.2th percentile
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | rex640_pcl1 | >= 1.0;0 < 1.0.8 | 1.0.8 |
| abb | rex640_pcl1_firmware | >= 1.0.0 < 1.0.8 | 1.0.8 |
| abb | rex640_pcl2 | >= 1.0;0 < 1.1.4 | 1.1.4 |
| abb | rex640_pcl2_firmware | >= 1.0.0 < 1.1.4 | 1.1.4 |
| abb | rex640_pcl3 | >= 1.0;0 < 1.2.1 | 1.2.1 |
| abb | rex640_pcl3_firmware | >= 1.0.0 < 1.2.1 | 1.2.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-13
Published