ZeroHour

CVE-2020-26732

CVSS 3.1
7.5 high
EPSS
2%p73
Published
()
Modified
Description

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

Vendors
skyworth
Products
gn542vf boa firmware
Weakness
CWE-311
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.