VYPR
Medium severity4.0NVD Advisory· Published Sep 29, 2016· Updated May 6, 2026

CVE-2016-7090

CVE-2016-7090

Description

SCALANCE M-800/S615 firmware <4.02 fails to set the secure flag on session cookies in HTTPS, enabling cookie theft via HTTP interception.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SCALANCE M-800/S615 firmware <4.02 fails to set the secure flag on session cookies in HTTPS, enabling cookie theft via HTTP interception.

Vulnerability

The integrated web server in Siemens SCALANCE M-800 and S615 modules with firmware versions before V4.02 sets session cookies without the Secure attribute over HTTPS sessions. This violates the CWE-614 guideline for sensitive cookies. The affected products are industrial routers (M-800) and security firewalls (S615) [1] [2].

Exploitation

A remote attacker with a privileged network position (e.g., man-in-the-middle on the same network segment) can intercept the session cookie when the victim's browser transmits it over an unencrypted HTTP session. The missing Secure flag allows the cookie to be sent over plain HTTP rather than enforcing HTTPS-only transmission [1].

Impact

Successful exploitation enables the attacker to capture the web session cookie and impersonate the authenticated user, leading to unauthorized access to the device's web management interface. This could allow exposure of configuration settings, modification of network routes, or disruption of industrial operations [1].

Mitigation

Siemens released firmware version V4.02 which addresses the issue. Users should upgrade to V4.02 or later. No workaround is documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities Catalog as of the publication date [1] [2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.