← Back

CVE-2016-7090

nvd nist
Published: Sep 29, 2016Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Affected (2)

2 products
Scalance M 800 Firmware
Scalance S615 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.01
Running on/withPlatform Versions
Siemens
Scalance M 800
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.01
Running on/withPlatform Versions
Siemens
Scalance S615
All versions

References (6)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.