PT-2015-5975 · Securifi · Securifi Almond+1
Joel Land
·
Published
2015-09-21
·
Updated
2015-09-30
·
CVE-2015-2917
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Securifi Almond devices with firmware prior to AL1-R201EXP10-L304-W34
Securifi Almond-2015 devices with firmware prior to AL2-R088M
Description
The issue makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a FRAME, IFRAME, or OBJECT element, due to the unintentional omission of the X-Frame-Options HTTP header.
Recommendations
For Securifi Almond devices with firmware prior to AL1-R201EXP10-L304-W34, update the firmware to AL1-R201EXP10-L304-W34 or later.
For Securifi Almond-2015 devices with firmware prior to AL2-R088M, update the firmware to AL2-R088M or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securifi Almond
Securifi Almond-2015