← Back to browse · API

CVE-2023-41084

Severity
CRITICAL
CVSS
10.0
EPSS
0.00579
Risk score
40.2
CISA KEV
No
PoC
No
Published
2023-09-18
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-45604, GHSA-C8F6-FGC7-QF74
Products
SOCOMEC:MODULYS GP (MOD3GP-SY-120K) v01.12.10
Sources
euvd EUVD-2023-45604

Description

Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

References