CVE-2023-4217
Last modified
CVE-2023-4217 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation. . EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Eds-G503 Firmware | < 5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4217?
How severe is CVE-2023-4217?
How do I fix CVE-2023-4217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4214The AppPresser plugin for WordPress is vulnerable to unautho…9.8
- CVE-2023-42143Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8…5.4
- CVE-2023-42144Cleartext Transmission during initial setup in Shelly TRV 20…5.5
- CVE-2023-42147An issue in CloudExplorer Lite 1.3.1 allows an attacker to o…7.5
- CVE-2023-4215Advantech WebAccess version 9.1.3 contains an exposure of se…7.5
- CVE-2023-4216The Orders Tracking for WooCommerce WordPress plugin before …2.7
- CVE-2023-42178Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the lo…6.5
- CVE-2023-4218In Eclipse IDE versions < 2023-09 (4.29) some files with xml…5
- CVE-2023-42180An arbitrary file upload vulnerability in the /user/upload c…8.8
- CVE-2023-42183lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 perf…5.3
- CVE-2023-42188IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (C…6.5
- CVE-2023-42189Insecure Permissions vulnerability in Connectivity Standards…7.5
Are you affected by CVE-2023-4217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
