ioLogik 4000 Series: Session Cookies Attribute Not Set Properly

CVE-2023-4228
4.3MEDIUM

Key Information

Vendor
Moxa
Status
ioLogik 4000 Series
Vendor
CVE Published:
24 August 2023

Summary

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

Affected Version(s)

ioLogik 4000 Series <= 1.6

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.