Web Server Cookie Vulnerability in SIMATIC Products by Siemens
CVE-2016-8672
5.3MEDIUM
Summary
A security flaw exists in certain SIMATIC products where the integrated web server transmits cookies without the 'secure' flag. This omission can lead to potential data leakage when cookies are sent over unencrypted connections. Modern web browsers recognize the 'secure' flag as a critical component for safe cookie transmission, making its absence a risk for exploitation, especially under clear text transmission scenarios. It is crucial for users to assess their systems and implement security measures to protect sensitive information from potential interception.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved