PT-2017-7717 · Arcadyan · Arcadyan Slt-00 Star

Mateusz Khalil

·

Published

2017-06-29

·

Updated

2017-07-07

·

CVE-2016-10042

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) versions prior to R7.7
Description The issue allows for an authorization bypass in the web interface, enabling unauthorized reconfiguration of the static routing table through an unauthenticated HTTP request. This can lead to denial of service and information disclosure.
Recommendations For versions prior to R7.7, update to version R7.7 or later to resolve the issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10042

Affected Products

Arcadyan Slt-00 Star