PT-2021-11266 · Skyworth · Skyworth Gn542Vf
Jiraput Thamsongkrah
·
Published
2021-01-14
·
Updated
2024-08-16
·
CVE-2020-26732
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16
SKYWORTH GN542VF Boa version 0.94.13
Description:
The issue is related to the session cookie in an HTTPS session not having the Secure flag set, making it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Recommendations:
For SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16, consider updating the software to a version that sets the Secure flag for the session cookie.
For SKYWORTH GN542VF Boa version 0.94.13, consider updating the Boa version to one that properly sets the Secure flag for the session cookie.
As a temporary workaround, consider restricting access to sensitive information transmitted over HTTP sessions until the issue is resolved.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skyworth Gn542Vf