7.5
CVSSv3

CVE-2021-37189

Published: 10/12/2021 Updated: 14/12/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Digi TransPort Gateway devices up to and including 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digi transport wr11 firmware

digi transport wr11 xt firmware

digi transport wr21 firmware

digi transport wr31 firmware

digi transport wr41 firmware

digi transport wr44 firmware