SSL/TLS Missing 'secure' Cookie Attribute, Report Weak Cipher Suites, Cleartext Transmission
SSL/TLS Missing 'secure' Cookie Attribute, Report Weak Cipher Suites, Cleartext Transmission
Having these errors for a couple of EAP 245 access points. They are showing up as vulnerable and there are no new firmware updates. Any news on fixes or firmware updates? Hasn't been one since February 2023.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Set the 'secure' attribute for any cookies that are sent over a SSL/TLS connection. Search "SSL/TLS Missing 'secure' Cookie AttributeSSL/TLS" on the Google.
- Copy Link
- Report Inappropriate Content
Thank you for your assistance. I'm wondering if that will fix all of these errors.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hello @rogerrabbit,
Thank you so much for taking the time to report the issue to our community!
What software did you use to scan and get these error messages?
Did you have any reports when you scan or get the error message?
rogerrabbit wrote
They are showing up as vulnerable and there are no new firmware updates.
In which procedure you encounter these error message?
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hi @rogerrabbit,
Could you elaborate on the network scanning device? Could you tell us the model number or the software name?
Could you share the full screenshot of the vulnerability scan procedure?
It is hard to locate the issue based on the information you current provide.
- Copy Link
- Report Inappropriate Content
I'm not sure what software it is. It's a 3rd party company that provides equipment. Here's some more info if it helps.
- Copy Link
- Report Inappropriate Content
Hi, i'm using the EAP 610 and used openvas for the scan and can confirm the statements. It is a shame that you cannot store your own HTTPS certificate in the management interface. I'm not even sure if you can disable or redirect the HTTP server on the web interface. I am currently trying to move the management interface to a separate VLAN and hang it behind a proxy. So far the web interface behind the HAProxy is not working yet. Website opens empty after the login... but maybe that strategie helps u too.
- Copy Link
- Report Inappropriate Content
I get the same erros from openvas on my EAP653 and EAP650-Wall
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 1000
Replies: 11
Voters 0
No one has voted for it yet.