Vulnerability Details CVE-2021-27463
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2021-27463
-
cpe:2.3:h:emerson:x-stream_enhanced_xefd:-
-
cpe:2.3:h:emerson:x-stream_enhanced_xegk:-
-
cpe:2.3:h:emerson:x-stream_enhanced_xegp:-
-
cpe:2.3:h:emerson:x-stream_enhanced_xexf:-
-
cpe:2.3:o:emerson:x-stream_enhanced_xefd_firmware:-
-
cpe:2.3:o:emerson:x-stream_enhanced_xegk_firmware:-
-
cpe:2.3:o:emerson:x-stream_enhanced_xegp_firmware:-
-
cpe:2.3:o:emerson:x-stream_enhanced_xexf_firmware:-