CVE-2021-34564
Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.03%
- CWE
- CWE-315
- Published
- 2021-08-31
- Last modified
- 2026-03-13
Affected products
- Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH
- Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
Weakness type
Related vulnerabilities
- CVE-2025-8528 — Exrick xboot getMenuList sensitive information in a cookie
- CVE-2025-4537 — yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
- CVE-2024-8644 — Cleartext Storage of Sensitive Information in Oceanic Software's ValeApp
- CVE-2024-24768 — 1Panel set-cookie is missing the Secure keyword
- CVE-2018-19941 — Cleartext Storage of Sensitive Information in Cookies