Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Vulnerability Type
HTTPS会话中未设置’Secure’属性的敏感Cookie
Vulnerability Title
Synology Router Manager 安全漏洞
Vulnerability Description
Synology Router Manager(SRM)是中国台湾群晖科技(Synology)公司的一款用于配置和管理Synology路由器的软件。 Synology Router Manager (SRM) 1.2.4-8081之前版本存在安全漏洞,该漏洞源于没有为HTTPS会话中的会话cookie设置安全标志,攻击者可利用该漏洞更容易通过拦截HTTP会话中的传输来捕获该cookie。
CVSS Information
N/A
Vulnerability Type
N/A