PT-2017-18716 · Mimosa · Mimosa Backhaul Radios+1
Published
2017-05-21
·
Updated
2017-05-26
·
CVE-2017-9134
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mimosa Client Radios versions prior to 2.2.3
Mimosa Backhaul Radios versions prior to 2.2.3
Description
An information-leakage issue allows unauthorized access to a device's serial number through a page in the web interface, without requiring login credentials. This issue is significant because another page, accessible without authentication, permits remote factory reset of the device by simply entering the serial number.
Recommendations
For Mimosa Client Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue.
For Mimosa Backhaul Radios versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mimosa Backhaul Radios
Mimosa Client Radios