PT-2017-5861 · Sagemcom · Livebox

Publicado

2017-11-15

·

Atualizado

2017-12-05

·

CVE-2014-3150

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Livebox version 1.1
Description: The issue allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
Recommendations: For Livebox version 1.1, consider restricting access to configuration files and sensitive information to prevent unauthorized uploads or downloads until a patch is available. As a temporary workaround, consider disabling Javascript execution in the Livebox interface to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3150

Produtos afetados

Livebox