PT-2017-18716 · Mimosa · Mimosa Backhaul Radios+1

Publicado

2017-05-21

·

Atualizado

2017-05-26

·

CVE-2017-9134

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mimosa Client Radios versions prior to 2.2.3 Mimosa Backhaul Radios versions prior to 2.2.3
Description An information-leakage issue allows unauthorized access to a device's serial number through a page in the web interface, without requiring login credentials. This issue is significant because another page, accessible without authentication, permits remote factory reset of the device by simply entering the serial number.
Recommendations For Mimosa Client Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue. For Mimosa Backhaul Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9134

Produtos afetados

Mimosa Backhaul Radios
Mimosa Client Radios