PT-2024-4577 · Unknown · Sinec Traffic Analyzer

Published

2024-06-11

·

Updated

2024-08-06

·

CVE-2024-35211

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SINEC Traffic Analyzer versions prior to V1.2
Description: A vulnerability has been identified in the affected web server of SINEC Traffic Analyzer. After a successful login, the web server sets the session cookie on the browser without applying security attributes such as Secure, HttpOnly, or SameSite. This issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations: For versions prior to V1.2, consider applying security attributes to the session cookie, such as setting Secure, HttpOnly, or SameSite, to minimize the risk of exploitation. As a temporary workaround, restrict access to sensitive information and consider implementing additional security measures to protect against unauthorized access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05083
CVE-2024-35211

Affected Products

Sinec Traffic Analyzer