Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.











Project Subscriptions

Vendors Products
Socomec Subscribe
Modulys Gp Subscribe
Modulys Gp Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-45604 Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.
Fixes

Solution

Socomec reports that MODULYS GP (MOD3GP-SY-120K) is an End-of-Life product. Socomec recommends using MODULYS GP2 (M4-S-XXX) instead. MODULYS GP2 (M4-S-XXX) is not affected by the above vulnerabilities.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T18:46:11.684Z

Reserved: 2023-09-06T15:41:16.509Z

Link: CVE-2023-41084

cve-icon Vulnrichment

Updated: 2024-08-02T18:46:11.684Z

cve-icon NVD

Status : Modified

Published: 2023-09-18T20:15:10.017

Modified: 2024-11-21T08:20:31.930

Link: CVE-2023-41084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses