8

CVE-2017-8334

Exploit
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Securifi ≫ Almond 2015 Firmware Version al-r096
   Securifi ≫ Almond 2015 Version -
Securifi ≫ Almond+firmware Version al-r096
   Securifi ≫ Almond+ Version -
Securifi ≫ Almond Firmware Version al-r096
   Securifi ≫ Almond Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8 2.1 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://seclists.org/bugtraq/2019/Jun/8
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/153227/Securifi-Almond-2015-Buffer-Overflow-Command-Injection-XSS-CSRF.html
Third Party Advisory
VDB Entry
https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Securifi_Almond_plus_sec_issues.pdf
Third Party Advisory
Exploit