Описание
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Ссылки
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
EPSS
5.8 Medium
CVSS3
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Уязвимость операционной системы Synology Router Manager (SRM), связанная с отсутствием флага «secure» в файлах cookie сеанса, позволяющая нарушителю получить несанкционированный доступ к целевому устройству
EPSS
5.8 Medium
CVSS3
8.1 High
CVSS3
6.8 Medium
CVSS2