CVE-2024-44575

RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:relyum:rely-pcie_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:relyum:rely-pcie:-:*:*:*:*:*:*:*

History

28 Apr 2025, 15:14

Type Values Removed Values Added
CPE cpe:2.3:o:relyum:rely-pcie_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:relyum:rely-pcie:-:*:*:*:*:*:*:*
First Time Relyum
Relyum rely-pcie
Relyum rely-pcie Firmware
References () http://system-on-chip.com - () http://system-on-chip.com - Broken Link
References () https://www.relyum.com/web/support/vulnerability-report/ - () https://www.relyum.com/web/support/vulnerability-report/ - Broken Link

25 Nov 2024, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7
CWE CWE-732

12 Sep 2024, 12:35

Type Values Removed Values Added
Summary
  • (es) RELY-PCIe v22.2.1 a v23.1.0 no establece el atributo Seguro para cookies confidenciales en sesiones HTTPS, lo que podría provocar que el agente de usuario envíe esas cookies en texto plano a través de una sesión HTTP.

11 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-11 17:15

Updated : 2025-04-28 15:14


NVD link : CVE-2024-44575

Mitre link : CVE-2024-44575

CVE.ORG link : CVE-2024-44575


JSON object : View

Products Affected

relyum

  • rely-pcie
  • rely-pcie_firmware
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource