PT-2004-1584 · Undefined · Undefined

Hiromitsu Takagi

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-0462

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Multiple networking devices (affected versions not specified)
Description The issue concerns the built-in web servers of multiple networking devices, which fail to set the Secure attribute for sensitive cookies during HTTPS sessions. This could lead to the user agent sending these cookies in plaintext over an HTTP session with the same server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0462

Affected Products

Undefined