CVE-2016-7090
4.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD
Description
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected (2)
Products: Siemens: Scalance M 800 Firmware, Scalance S615 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.01 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M 800 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.01 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance S615 | All versions |
References (6)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.