CVE-2020-26732
Summary
| CVE | CVE-2020-26732 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-14 16:15:00 UTC |
| Updated | 2023-02-03 18:55:00 UTC |
| Description | SKYWORTH GN542VF Boa version 0.94.13 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Skyworth | Gn542vf Boa | - | All | All | All |
| Hardware | Skyworth | Gn542vf Boa | - | All | All | All |
| Operating System | Skyworth | Gn542vf Boa Firmware | 0.94.13 | All | All | All |
| Operating System | Skyworth | Gn542vf Boa Firmware | 0.94.13 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - swzhouu/CVE-2020-26732: Skyworth GN542VF Boa version 0.94.13 does not set the Secure flag for the session cookie in an HTTPS session | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.