PT-2019-8650 · Vera · Veraedge+1

Mandar Satam

·

Publicado

2019-06-17

·

Atualizado

2019-06-20

·

CVE-2017-9381

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vera VeraEdge version 1.7.19 Vera Veralite version 1.7.481
Description An issue was discovered where the device does not implement any cross-site request forgery protection mechanism. This allows an attacker to trick a user who navigates to an attacker-controlled page to install or delete an application on the device using the web management interface. The cross-site request forgery is a systemic issue across all other functionalities of the device.
Recommendations For Vera VeraEdge version 1.7.19, consider disabling the web management interface until a patch is available to prevent exploitation. For Vera Veralite version 1.7.481, restrict access to the web management interface to minimize the risk of exploitation. As a temporary workaround, avoid using the web management interface to install or delete applications until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9381

Produtos afetados

Veraedge
Veralite