PT-2017-18716 · Mimosa · Mimosa Backhaul Radios+1

Published

2017-05-21

·

Updated

2017-05-26

·

CVE-2017-9134

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mimosa Client Radios versions prior to 2.2.3 Mimosa Backhaul Radios versions prior to 2.2.3
Description An information-leakage issue allows unauthorized access to a device's serial number through a page in the web interface, without requiring login credentials. This issue is significant because another page, accessible without authentication, permits remote factory reset of the device by simply entering the serial number.
Recommendations For Mimosa Client Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue. For Mimosa Backhaul Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9134

Affected Products

Mimosa Backhaul Radios
Mimosa Client Radios