CVE-2015-7296
- EPSS 1.11%
- Veröffentlicht 21.09.2015 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which ...
CVE-2015-2917
- EPSS 0.93%
- Veröffentlicht 21.09.2015 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attack...
CVE-2015-2916
- EPSS 0.11%
- Veröffentlicht 21.09.2015 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M allows remote attackers to hijack the authentication of arbitrary users.
CVE-2015-2915
- EPSS 0.29%
- Veröffentlicht 21.09.2015 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M have a default password of admin for the admin account, which allows remote attackers to obtain web-management access by levera...
- EPSS 0.82%
- Veröffentlicht 21.09.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a fixed source-port number in outbound DNS queries performed on behalf of any device, which makes it easier for remote atta...