First published: Thu May 20 2021(Updated: )
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson X-stream Enhanced Xegp Firmware | ||
Emerson X-stream Enhanced Xegp | ||
Emerson X-stream Enhanced Xegk Firmware | ||
Emerson X-stream Enhanced Xegk | ||
Emerson X-stream Enhanced Xefd Firmware | ||
Emerson X-stream Enhanced Xefd | ||
Emerson X-stream Enhanced Xexf Firmware | ||
Emerson X-stream Enhanced Xexf | ||
Emerson X-STREAM enhanced XEGP – all revisions | ||
Emerson X-STREAM enhanced XEGK – all revisions | ||
Emerson X-STREAM enhanced XEFD – all revisions | ||
Emerson X-STREAM enhanced XEXF – all revisions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27463.
The severity of CVE-2021-27463 is medium with a severity value of 5.3.
Multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer are affected, including X-stream Enhanced Xegp Firmware, X-stream Enhanced Xegk Firmware, X-stream Enhanced Xefd Firmware, and X-stream Enhanced Xexf Firmware.
This vulnerability allows an attacker to intercept the persistent cookies used by the affected applications, thereby gaining access to sensitive information.
Emerson X-stream Enhanced Xegp is vulnerable to CVE-2021-27463.