CVE-2020-29024: Missing HtppOnly and Secure flags
Published Feb 16, 2021
·Updated
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.
Affected Software
8 affected components
Secomea Gatemanager 4250 Firmware
Secomea Gatemanager 4250
Secomea Gatemanager 4260 Firmware
Secomea Gatemanager 4260
Secomea Gatemanager 9250 Firmware
Secomea Gatemanager 9250
Secomea Gatemanager 8250 Firmware<9.3
Secomea Gatemanager 8250
Event History
Feb 16, 2021
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-29024.
2
What is the severity of CVE-2020-29024?
The severity of CVE-2020-29024 is medium with a severity value of 5.3.
3
Which software versions are affected by CVE-2020-29024?
CVE-2020-29024 affects Secomea GateManager all versions prior to 9.3.
4
How can an attacker exploit CVE-2020-29024?
An attacker can exploit CVE-2020-29024 to gain access to sensitive cookies by leveraging the missing 'Secure' attribute in the HTTPS session.
5
Is there a fix available for CVE-2020-29024?
Yes, a fix is available for CVE-2020-29024. It is recommended to update to Secomea GateManager version 9.3 or later.