CVE-2021-37189

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
10/12/2021
Last modified:
14/12/2021

Description

An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:digi:transport_wr11_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr11:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr11_xt_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr11_xt:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr21_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr21:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr31_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr31:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr41_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr41:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr44_firmware:*:*:*:*:*:*:*:* 6.0.0.0 (excluding)
cpe:2.3:h:digi:transport_wr44:v2:*:*:*:*:*:*:*