216.73.216.36

CVE-2024-41685

· Published 26/07/2024 12:15 · Modified 26/07/2024 12:38

Labels: CVE-2024-41685 2024-07-26CVE-2024-41685CWE-1004[email protected]

Essential information

Published
26/07/2024 12:15
Modified
26/07/2024 12:38
Author
Creator
CISA KEV
No
CWE

Description

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to capture cookies and obtain sensitive information on the targeted system.

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References