← Back

CVE-2021-37189

nvd nist
Published: Dec 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

Affected (6)

6 products
Transport Wr11 Firmware
Transport Wr11 Xt Firmware
Transport Wr21 Firmware
Transport Wr31 Firmware
Transport Wr41 Firmware
Transport Wr44 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr11
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr11 Xt
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr21
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr31
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr41
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.0.0.0
Running on/withPlatform Versions
Digi
Transport Wr44
Version v2

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.