PT-2021-11266 · Skyworth · Skyworth Gn542Vf

Jiraput Thamsongkrah

·

Published

2021-01-14

·

Updated

2024-08-16

·

CVE-2020-26732

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 SKYWORTH GN542VF Boa version 0.94.13
Description: The issue is related to the session cookie in an HTTPS session not having the Secure flag set, making it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Recommendations: For SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16, consider updating the software to a version that sets the Secure flag for the session cookie. For SKYWORTH GN542VF Boa version 0.94.13, consider updating the Boa version to one that properly sets the Secure flag for the session cookie. As a temporary workaround, consider restricting access to sensitive information transmitted over HTTP sessions until the issue is resolved.

Exploit

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2020-26732

Affected Products

Skyworth Gn542Vf