Web Server Cookie Vulnerability in SIMATIC Products by Siemens
CVE-2016-8672

5.3MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
23 November 2016

Summary

A security flaw exists in certain SIMATIC products where the integrated web server transmits cookies without the 'secure' flag. This omission can lead to potential data leakage when cookies are sent over unencrypted connections. Modern web browsers recognize the 'secure' flag as a critical component for safe cookie transmission, making its absence a risk for exploitation, especially under clear text transmission scenarios. It is crucial for users to assess their systems and implement security measures to protect sensitive information from potential interception.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.