PT-2019-8624 · Securifi · Securifi Almond+1
Mandar Satam
·
Published
2019-06-18
·
Updated
2019-06-21
·
CVE-2017-8337
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Securifi Almond version AL-R096
Securifi Almond+ version AL-R096
Securifi Almond 2015 version AL-R096
Description
The issue allows an attacker to exploit the lack of Origin header check on the web management interface. This enables the attacker to trick a user into navigating to a malicious webpage, brute force the password, and execute actions such as managing rules and sensors attached to the devices using websocket requests.
Recommendations
For Securifi Almond version AL-R096, consider disabling access to the web management interface until a patch is available.
For Securifi Almond+ version AL-R096, restrict access to the websocket requests to minimize the risk of exploitation.
For Securifi Almond 2015 version AL-R096, avoid using the web management interface for sensitive actions until the issue is resolved.
As a temporary workaround, consider implementing additional security measures to prevent brute force attacks on the password for the web management interface.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securifi Almond
Securifi Almond-2015