PT-2023-6852 · Unknown · Pt-G503 Series

CVE-2023-4217

·

Published

2023-08-08

·

Updated

2023-11-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PT-G503 Series versions prior to v5.2
Description A vulnerability has been identified where the session cookies attribute is not set properly in the affected application, potentially exposing user session data to unauthorized access and manipulation. The vulnerability is related to the use of cookies for storing confidential information without the HttpOnly flag.
Recommendations For PT-G503 Series versions prior to v5.2, consider updating to version v5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to session cookies to minimize the risk of exploitation. Avoid using the session cookies attribute in the affected application until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07861
CVE-2023-4217

Affected Products

Pt-G503 Series