PT-2017-7717 · Arcadyan · Arcadyan Slt-00 Star
Mateusz Khalil
·
Published
2017-06-29
·
Updated
2017-07-07
·
CVE-2016-10042
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) versions prior to R7.7
Description
The issue allows for an authorization bypass in the web interface, enabling unauthorized reconfiguration of the static routing table through an unauthenticated HTTP request. This can lead to denial of service and information disclosure.
Recommendations
For versions prior to R7.7, update to version R7.7 or later to resolve the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadyan Slt-00 Star