Endress+Hauser MEAC300-FNADE4 Missing Secure Attribute on Cookies Vulnerability
Vulnerability
A vulnerability exists in the Endress+Hauser MEAC300-FNADE4 due to the absence of the Secure attribute on multiple cookies, including the PHPSESSID cookie. This flaw allows an attacker to intercept unencrypted HTTP requests and access the sensitive cookie information. The vulnerability is present in all versions of the MEAC300-FNADE4 firmware.
Impact
Exploitation of this vulnerability allows for the interception of cookies, including session identifiers, which can be used to hijack user sessions or impersonate users.
Remediation
Users are advised to update the Endress+Hauser MEAC300-FNADE4 to the latest version. General security practices should also be applied to minimize network exposure and restrict access to the device.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
