An issue exists on Digi TransPort Gateway devices up to and including 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digi transport wr11 firmware |
||
digi transport wr11 xt firmware |
||
digi transport wr21 firmware |
||
digi transport wr31 firmware |
||
digi transport wr41 firmware |
||
digi transport wr44 firmware |