PT-2021-11266 · Skyworth · Skyworth Gn542Vf

·

CVE-2020-26732

·

Published

2021-01-14

·

Updated

2024-08-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 SKYWORTH GN542VF Boa version 0.94.13
Description: The issue is related to the session cookie in an HTTPS session not having the Secure flag set, making it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Recommendations: For SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16, consider updating the software to a version that sets the Secure flag for the session cookie. For SKYWORTH GN542VF Boa version 0.94.13, consider updating the Boa version to one that properly sets the Secure flag for the session cookie. As a temporary workaround, consider restricting access to sensitive information transmitted over HTTP sessions until the issue is resolved.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26732

Affected Products

Skyworth Gn542Vf