PT-2019-8624 · Securifi · Securifi Almond+1
Mandar Satam
·
Publicado
2019-06-18
·
Atualizado
2019-06-21
·
CVE-2017-8337
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Securifi Almond version AL-R096
Securifi Almond+ version AL-R096
Securifi Almond 2015 version AL-R096
Description
The issue allows an attacker to exploit the lack of Origin header check on the web management interface. This enables the attacker to trick a user into navigating to a malicious webpage, brute force the password, and execute actions such as managing rules and sensors attached to the devices using websocket requests.
Recommendations
For Securifi Almond version AL-R096, consider disabling access to the web management interface until a patch is available.
For Securifi Almond+ version AL-R096, restrict access to the websocket requests to minimize the risk of exploitation.
For Securifi Almond 2015 version AL-R096, avoid using the web management interface for sensitive actions until the issue is resolved.
As a temporary workaround, consider implementing additional security measures to prevent brute force attacks on the password for the web management interface.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Securifi Almond
Securifi Almond-2015