CVE-2023-5035 is a medium-severity vulnerability affecting Moxa PT-G503 Series firmware versions prior to v5.2. It stems from sensitive cookies lacking the "Secure" attribute in HTTPS sessions, potentially leading to their transmission in plaintext over HTTP. This flaw could expose user session data to unauthorized access and manipulation, with a CVSS score of 5.3. Currently, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. Community discussion and media coverage are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2CPE matchmatch criteria | cpe:2.3:o:moxa:eds-g503_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.