PT-2019-8650 · Vera · Veraedge+1
Mandar Satam
·
Published
2019-06-17
·
Updated
2019-06-20
·
CVE-2017-9381
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vera VeraEdge version 1.7.19
Vera Veralite version 1.7.481
Description
An issue was discovered where the device does not implement any cross-site request forgery protection mechanism. This allows an attacker to trick a user who navigates to an attacker-controlled page to install or delete an application on the device using the web management interface. The cross-site request forgery is a systemic issue across all other functionalities of the device.
Recommendations
For Vera VeraEdge version 1.7.19, consider disabling the web management interface until a patch is available to prevent exploitation.
For Vera Veralite version 1.7.481, restrict access to the web management interface to minimize the risk of exploitation.
As a temporary workaround, avoid using the web management interface to install or delete applications until the issue is resolved.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veraedge
Veralite