Home
MEDIUM: 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NMEDIUM: 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unknown
Any version before V4.0
affected
Description
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.
Problem types
CWE-525: Use of Web Browser Cache Containing Sensitive Information
Product status
Any version before V4.0
References
cert-portal.siemens.com/productcert/html/ssa-253495.html