PT-2017-6771 · Hak5 · Wifi Pineapple

Catatonicprime

·

Published

2017-03-31

·

Updated

2018-10-09

·

CVE-2015-4624

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hak5 WiFi Pineapple versions 2.0 through 2.3
Description The issue concerns the use of predictable CSRF tokens.
Recommendations For versions 2.0 through 2.3, consider disabling CSRF token generation until a patch is available, or apply configuration changes to utilize a more secure token generation mechanism.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4624

Affected Products

Wifi Pineapple