CVE-2022-26157 describes a vulnerability in Cherwell Service Management (CSM) 10.2.3 where the ASP.NET_Sessionid cookie lacks the Secure flag. This omission allows for potential interception of session cookies by an attacker if communication occurs over unencrypted HTTP channels, leading to a CVSS score of 5.3 (Medium). While the vulnerability has a low EPSS score and no known active exploitation, public exploit code, or significant community discussion, it still presents a risk of sensitive information disclosure. Organizations using affected versions should consider implementing secure communication protocols to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.3CPE matchmatch criteria | cpe:2.3:a:cherwell:cherwell_service_management:10.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.