PT-2017-5861 · Sagemcom · Livebox
Published
2017-11-15
·
Updated
2017-12-05
·
CVE-2014-3150
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Livebox version 1.1
Description:
The issue allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
Recommendations:
For Livebox version 1.1, consider restricting access to configuration files and sensitive information to prevent unauthorized uploads or downloads until a patch is available. As a temporary workaround, consider disabling Javascript execution in the Livebox interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livebox