Aller au contenu

Fiche vulnérabilité

CVE-2025-27453 : faille moyenne endress meac300-fnade4 firmware (CVSS 6.5)

Description

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • endress meac300-fnade4 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE