CVE-2021-37189
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr11 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr11 Xt | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr21 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr31 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr41 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr44 | Version v2 |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.