2023-11-02 19:00:23 +00:00
{
"id" : "CVE-2023-4217" ,
"sourceIdentifier" : "psirt@moxa.com" ,
"published" : "2023-11-02T17:15:11.610" ,
2023-11-09 21:00:22 +00:00
"lastModified" : "2023-11-09T19:47:38.290" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-11-02 19:00:23 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.\n\n"
2023-11-09 21:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se identific\u00f3 una vulnerabilidad en las versiones Series PT-G503 anteriores a la v5.2, donde el atributo de cookies de sesi\u00f3n no est\u00e1 configurado correctamente en la aplicaci\u00f3n afectada. La vulnerabilidad puede generar riesgos de seguridad, exponiendo potencialmente los datos de la sesi\u00f3n del usuario a acceso y manipulaci\u00f3n no autorizados."
2023-11-02 19:00:23 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-09 21:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
} ,
2023-11-02 19:00:23 +00:00
{
"source" : "psirt@moxa.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.1 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2023-11-09 21:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-668"
}
]
} ,
2023-11-02 19:00:23 +00:00
{
"source" : "psirt@moxa.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-1004"
}
]
}
] ,
2023-11-09 21:00:22 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:moxa:eds-g503:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80A7E418-48BA-42E7-B0C6-AD9A3F1E18E8"
2023-11-09 21:00:22 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:moxa:eds-g503_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.2" ,
"matchCriteriaId" : "FEE72D70-1B7F-4F7C-ABA5-1542A0B4DC64"
2023-11-09 21:00:22 +00:00
}
]
}
]
}
] ,
2023-11-02 19:00:23 +00:00
"references" : [
{
"url" : "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230203-pt-g503-series-multiple-vulnerabilities" ,
2023-11-09 21:00:22 +00:00
"source" : "psirt@moxa.com" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2023-11-02 19:00:23 +00:00
}
]
}