CVE-2021-34563: In WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side javascript to modify it
Published Aug 31, 2021
·Updated
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
Affected Software
6 affected components
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth Firmware=3.0.8
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth Firmware=3.0.9
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware=3.0.8
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware=3.0.9
Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip
Remediation
Information
No update available.
Event History
Aug 31, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-34563.
2
What is the severity of CVE-2021-34563?
The severity of CVE-2021-34563 is low.
3
Which versions of PEPPERL+FUCHS WirelessHART-Gateway are affected?
PEPPERL+FUCHS WirelessHART-Gateway versions 3.0.8 and 3.0.9 are affected.
4
What is the impact of this vulnerability?
This vulnerability allows the cookie's value to be read or set by client-side JavaScript.
5
Is there a fix for this vulnerability?
No information regarding a fix for this vulnerability is provided.