PT-2016-2696 · Vesp · Vesp211-Eu+1
Maxim Rupp
·
Publicado
2016-02-21
·
Atualizado
2016-03-10
·
CVE-2016-2275
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VESP211-EU devices version 1.7.2
VESP211-232 devices versions 1.5.1 through 1.7.2
Description
The issue is related to the web interface of the affected devices, which relies on client-side access control. This allows remote attackers to perform administrative actions by modifying JavaScript code. The vulnerability can be exploited to execute administrative actions remotely.
Recommendations
For VESP211-EU devices version 1.7.2, consider disabling the web interface until a patch is available.
For VESP211-232 devices versions 1.5.1 through 1.7.2, restrict access to the web interface to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vesp211-232
Vesp211-Eu