Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens Scalance M-800和S615 安全漏洞
Vulnerability Description
Siemens Scalance M-800和S615都是德国西门子(Siemens)公司的产品。前者是一款工业路由器,后者是一款防火墙。 使用4.02之前版本固件的Siemens SCALANCE M-800和S615模块上的综合Web服务器存在安全漏洞,该漏洞源于程序没有对https会话中的cookie设置安全标志。远程攻击者可通过截取http会话传输利用该漏洞获取cookie。
CVSS Information
N/A
Vulnerability Type
N/A