HIGH🇬🇧 English

CVE-2021-37189

CVSS 7.5v3.1pub. 2021-12-10upd. 2024-11-21

An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Digi Transport Wr11

    HW
    Digi
    wszystkie wersje
  • Digi Transport Wr11 Firmware

    OS
    Digi
    < 6.0.0.0
  • Digi Transport Wr11 Xt

    HW
    Digi
    wszystkie wersje
  • Digi Transport Wr11 Xt Firmware

    OS
    Digi
    < 6.0.0.0
  • Digi Transport Wr21

    HW
    Digi
    wszystkie wersje
  • Digi Transport Wr21 Firmware

    OS
    Digi
    < 6.0.0.0
  • Digi Transport Wr31

    HW
    Digi
    wszystkie wersje
  • Digi Transport Wr31 Firmware

    OS
    Digi
    < 6.0.0.0
  • Digi Transport Wr41

    HW
    Digi
    wszystkie wersje
  • Digi Transport Wr41 Firmware

    OS
    Digi
    < 6.0.0.0
  • Digi Transport Wr44

    HW
    Digi
    v2
  • Digi Transport Wr44 Firmware

    OS
    Digi
    < 6.0.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-4299CRITICAL9.0PL ✓ten sam produkt

Digi RealPort Protocol — podatność na atak replay umożliwiająca ominięcie uwierzytelnienia

CVE-2021-35978CRITICAL9.8PL ✓ten sam produkt

RCE z uprawnieniami SUPER w protokole ZING urządzeń Digi TransPort

CVE-2021-36767CRITICAL9.8PL ✓ten sam produkt

Digi RealPort — słabe haszowanie hasła umożliwia nieautoryzowany dostęp

CVE-2021-35977CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w Digi RealPort — wykonanie dowolnego kodu przez ADDP

CVE-2021-37188HIGH8.8ten sam produkt

An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load custo...