CVE-2023-2876: Abb REX640 PCL1 Firmware
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.
Affected products
- Abb REX640 PCL1 Firmware: from 1.0.0, before 1.0.8 (fixed in 1.0.8)
- Abb REX640 PCL2 Firmware: from 1.0.0, before 1.1.4 (fixed in 1.1.4)
- Abb REX640 PCL3 Firmware: from 1.0.0, before 1.2.1 (fixed in 1.2.1)
Published 2023-06-13. Last modified 2026-06-17.