Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2876


Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.


Published

2023-06-13T04:15:10.307

Last Modified

2024-11-21T07:59:28.573

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.1 (LOW)

Weaknesses
  • Type: Secondary
    CWE-1004
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System abb rex640_pcl1_firmware < 1.0.8 Yes
Hardware abb rex640_pcl1 - No
Operating System abb rex640_pcl2_firmware < 1.1.4 Yes
Hardware abb rex640_pcl2 - No
Operating System abb rex640_pcl3_firmware < 1.2.1 Yes
Hardware abb rex640_pcl3 - No

References