PT-2019-8650 · Vera · Veraedge+1

Mandar Satam

·

Published

2019-06-17

·

Updated

2019-06-20

·

CVE-2017-9381

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vera VeraEdge version 1.7.19 Vera Veralite version 1.7.481
Description An issue was discovered where the device does not implement any cross-site request forgery protection mechanism. This allows an attacker to trick a user who navigates to an attacker-controlled page to install or delete an application on the device using the web management interface. The cross-site request forgery is a systemic issue across all other functionalities of the device.
Recommendations For Vera VeraEdge version 1.7.19, consider disabling the web management interface until a patch is available to prevent exploitation. For Vera Veralite version 1.7.481, restrict access to the web management interface to minimize the risk of exploitation. As a temporary workaround, avoid using the web management interface to install or delete applications until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9381

Affected Products

Veraedge
Veralite