PT-2017-7717 · Arcadyan · Arcadyan Slt-00 Star
Mateusz Khalil
·
Publicado
2017-06-29
·
Atualizado
2017-07-07
·
CVE-2016-10042
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) versions prior to R7.7
Description
The issue allows for an authorization bypass in the web interface, enabling unauthorized reconfiguration of the static routing table through an unauthenticated HTTP request. This can lead to denial of service and information disclosure.
Recommendations
For versions prior to R7.7, update to version R7.7 or later to resolve the issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Arcadyan Slt-00 Star