An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
References
Link | Resource |
---|---|
https://raw.githubusercontent.com/reidmefirst/vuln-disclosure/main/2021-04.txt | Third Party Advisory |
https://www.digi.com/search/results?q=transport | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Information
Published : 2021-12-10 05:15
Updated : 2021-12-14 09:18
NVD link : CVE-2021-37189
Mitre link : CVE-2021-37189
JSON object : View
CWE
CWE-311
Missing Encryption of Sensitive Data
Products Affected
digi
- transport_wr44_firmware
- transport_wr31
- transport_wr21_firmware
- transport_wr41_firmware
- transport_wr11_xt_firmware
- transport_wr44
- transport_wr11_firmware
- transport_wr11_xt
- transport_wr11
- transport_wr41
- transport_wr31_firmware
- transport_wr21