An issue exists on Digi TransPort Gateway devices up to and including 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digi transport_wr11_firmware |
||
digi transport_wr11_xt_firmware |
||
digi transport_wr21_firmware |
||
digi transport_wr31_firmware |
||
digi transport_wr41_firmware |
||
digi transport_wr44_firmware |