CVE Vulnerabilities

CVE-2024-35211

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Jun 11, 2024 | Modified: Feb 11, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

NameVendorStart VersionEnd Version
Sinec_traffic_analyzerSiemens*1.2 (excluding)

Potential Mitigations

References