CVE-2023-2876

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abb:rex640_pcl1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:abb:rex640_pcl2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:abb:rex640_pcl3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 3.1
References () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001423&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001423&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory

26 Jun 2023, 17:42

Type Values Removed Values Added
First Time Abb rex640 Pcl2
Abb
Abb rex640 Pcl1 Firmware
Abb rex640 Pcl2 Firmware
Abb rex640 Pcl1
Abb rex640 Pcl3
Abb rex640 Pcl3 Firmware
CPE cpe:2.3:h:abb:rex640_pcl2:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl1:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl3:-:*:*:*:*:*:*:*
cpe:2.3:o:abb:rex640_pcl1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:rex640_pcl2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:rex640_pcl3_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References (MISC) https://search.abb.com/library/Download.aspx?DocumentID=2NGA001423&LanguageCode=en&DocumentPartId=&Action=Launch - (MISC) https://search.abb.com/library/Download.aspx?DocumentID=2NGA001423&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory
CWE CWE-1004 CWE-732

13 Jun 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 04:15

Updated : 2024-11-21 07:59


NVD link : CVE-2023-2876

Mitre link : CVE-2023-2876

CVE.ORG link : CVE-2023-2876


JSON object : View

Products Affected

abb

  • rex640_pcl1_firmware
  • rex640_pcl2
  • rex640_pcl2_firmware
  • rex640_pcl1
  • rex640_pcl3_firmware
  • rex640_pcl3
CWE
CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag

CWE-732

Incorrect Permission Assignment for Critical Resource