IM
IronMonkey Threat Research

CVE-2017-5141 MEDIUM

Published: 2017-02-13 | Last Modified: 2026-06-17 | Status: Modified

Description

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION).

Additional Descriptions (1)

Ha sido descubierto un problema en el controlador XL1000C500 XLWebExe-2-01-00 de XLWebExe-2 y anteriores y XLWebExe-1-02-08 y anteriores de XLWebExe-1-02-08 de Honeywell XL Web. Un atacante puede establecer una nueva sesión de usuario, sin invalidar ningún identificador de sesión existente, lo que le da la oportunidad de robar sesiones autenticadas (REPARACIÓN DE SESIÓN).

CVSS Metrics

Base Score: 6.5 (MEDIUM)

AV:N/AC:L/Au:S/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-384

Affected Products

Vendor Product Version Update Type
honeywell xl_web_ii_controller xlwebexe-1-02-08 <built-in method update of dict object at 0x7c3c40dd7480> Operating System
honeywell xl_web_ii_controller xlwebexe-2-01-00 <built-in method update of dict object at 0x7c3c40d56440> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:honeywell:xl_web_ii_controller:xlwebexe-1-02-08:*:*:*:*:*:*:*
Yes cpe:2.3:o:honeywell:xl_web_ii_controller:xlwebexe-2-01-00:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:honeywell:xl_web_ii_controller:-:*:*:*:*:*:*:*

References

Notification
Message here