PT-2017-5861 · Sagemcom · Livebox

Published

2017-11-15

·

Updated

2017-12-05

·

CVE-2014-3150

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Livebox version 1.1
Description: The issue allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
Recommendations: For Livebox version 1.1, consider restricting access to configuration files and sensitive information to prevent unauthorized uploads or downloads until a patch is available. As a temporary workaround, consider disabling Javascript execution in the Livebox interface to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3150

Affected Products

Livebox