PT-2019-10793 · Sierra Wireless · Sierra Wireless Airlink Es450

Carl Hurd

+1

·

Publicado

2019-05-06

·

Atualizado

2019-05-07

·

CVE-2018-4066

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless AirLink ES450 FW version 4.9.3
Description A cross-site request forgery issue exists in the ACEManager functionality. This allows an attacker to trick an authenticated user into making unintended requests, potentially leading to unauthorized access. The attacker can exploit this to get an authenticated user to request pages on their behalf.
Recommendations For Sierra Wireless AirLink ES450 FW version 4.9.3, consider implementing additional validation for HTTP requests to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the ACEManager functionality to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-4066

Produtos afetados

Sierra Wireless Airlink Es450