PT-2017-18716 · Mimosa · Mimosa Backhaul Radios+1
Publicado
2017-05-21
·
Atualizado
2017-05-26
·
CVE-2017-9134
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mimosa Client Radios versions prior to 2.2.3
Mimosa Backhaul Radios versions prior to 2.2.3
Description
An information-leakage issue allows unauthorized access to a device's serial number through a page in the web interface, without requiring login credentials. This issue is significant because another page, accessible without authentication, permits remote factory reset of the device by simply entering the serial number.
Recommendations
For Mimosa Client Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue.
For Mimosa Backhaul Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mimosa Backhaul Radios
Mimosa Client Radios