Vulnerability Name: | CVE-2004-0462 (CCN-17702) | ||||||||
Assigned: | 2004-10-12 | ||||||||
Published: | 2004-10-12 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0462 Source: CCN Type: US-CERT VU#546483 Multiple networking devices fail to set the "Secure" attribute of a cookie Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#546483 Source: CCN Type: OSVDB ID: 19183 Multiple Networking Device HTTPS Session Cookie Secure Attribute Set Failure Source: XF Type: UNKNOWN network-device-secure-plaintext(17702) Source: XF Type: UNKNOWN network-device-secure-plaintext(17702) | ||||||||
BACK |