Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:Y/R:U/RE:M/U:ClearDefault status
unaffected
16.0.0 (cpe)
affected
15.0.0 (cpe)
affected
12.0.0 (cpe)
affected
Description
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.
Problem types
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CWE-1275 Sensitive Cookie with Improper SameSite Attribute
Product status
16.0.0 (cpe)
15.0.0 (cpe)
12.0.0 (cpe)
References
www.pcvue.com/security/