CVE-2021-27463 Vulnerability Details

  /     /     /  

CVE-2021-27463 Metadata Quick Info

CVE Published: 20/05/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: icscert | Vendor: n/a | Product: Emerson Rosemount X-STREAM Gas Analyzer
Status : PUBLISHED

CVE-2021-27463 Description

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-539
CWE Name: USE OF PERSISTENT COOKIES CONTAINING SENSITIVE INFORMATION CWE-539
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).