Security Advisory

CVE-2025-27450

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-03 11:26:33
Last updated 2025-07-03 13:16:27
Assigner SICK AG
CVSS score not scored
State PUBLISHED

Description

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.