CVE Vulnerabilities

CVE-2020-27651

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Oct 29, 2020 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

NameVendorStart VersionEnd Version
Router_managerSynology1.2 (including)1.2.4-8081 (excluding)

Potential Mitigations

References