PT-2016-2696 · Vesp · Vesp211-Eu+1

Maxim Rupp

·

Publicado

2016-02-21

·

Atualizado

2016-03-10

·

CVE-2016-2275

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VESP211-EU devices version 1.7.2 VESP211-232 devices versions 1.5.1 through 1.7.2
Description The issue is related to the web interface of the affected devices, which relies on client-side access control. This allows remote attackers to perform administrative actions by modifying JavaScript code. The vulnerability can be exploited to execute administrative actions remotely.
Recommendations For VESP211-EU devices version 1.7.2, consider disabling the web interface until a patch is available. For VESP211-232 devices versions 1.5.1 through 1.7.2, restrict access to the web interface to minimize the risk of exploitation.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02088
CVE-2016-2275

Produtos afetados

Vesp211-232
Vesp211-Eu