Vulnerabilities > CVE-2024-41684 - Unspecified vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
syrotech

Summary

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to capture cookies and compromise the targeted system.

Vulnerable Configurations

Part Description Count
OS
Syrotech
1
Hardware
Syrotech
1