PT-2015-5975 · Securifi · Securifi Almond+1

Joel Land

·

Published

2015-09-21

·

Updated

2015-09-30

·

CVE-2015-2917

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Securifi Almond devices with firmware prior to AL1-R201EXP10-L304-W34 Securifi Almond-2015 devices with firmware prior to AL2-R088M
Description The issue makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a FRAME, IFRAME, or OBJECT element, due to the unintentional omission of the X-Frame-Options HTTP header.
Recommendations For Securifi Almond devices with firmware prior to AL1-R201EXP10-L304-W34, update the firmware to AL1-R201EXP10-L304-W34 or later. For Securifi Almond-2015 devices with firmware prior to AL2-R088M, update the firmware to AL2-R088M or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2917

Affected Products

Securifi Almond
Securifi Almond-2015