PT-2023-27776 · Furuno Systems · Acera 1110+11
Published
2023-10-02
·
Updated
2023-10-04
·
CVE-2023-41086
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FURUNO SYSTEMS ACERA 1210 firmware versions 02.36 and earlier
FURUNO SYSTEMS ACERA 1150i firmware versions 01.35 and earlier
FURUNO SYSTEMS ACERA 1150w firmware versions 01.35 and earlier
FURUNO SYSTEMS ACERA 1110 firmware versions 01.76 and earlier
FURUNO SYSTEMS ACERA 1020 firmware versions 01.86 and earlier
FURUNO SYSTEMS ACERA 1010 firmware versions 01.86 and earlier
FURUNO SYSTEMS ACERA 950 firmware versions 01.60 and earlier
FURUNO SYSTEMS ACERA 850F firmware versions 01.60 and earlier
FURUNO SYSTEMS ACERA 900 firmware versions 02.54 and earlier
FURUNO SYSTEMS ACERA 850M firmware versions 02.06 and earlier
FURUNO SYSTEMS ACERA 810 firmware versions 03.74 and earlier
FURUNO SYSTEMS ACERA 800ST firmware versions 07.35 and earlier
Description
A cross-site request forgery (CSRF) issue exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. The affected devices are vulnerable when running in ST (Standalone) mode.
Recommendations
For FURUNO SYSTEMS ACERA 1210 firmware versions 02.36 and earlier, update to a version later than 02.36.
For FURUNO SYSTEMS ACERA 1150i firmware versions 01.35 and earlier, update to a version later than 01.35.
For FURUNO SYSTEMS ACERA 1150w firmware versions 01.35 and earlier, update to a version later than 01.35.
For FURUNO SYSTEMS ACERA 1110 firmware versions 01.76 and earlier, update to a version later than 01.76.
For FURUNO SYSTEMS ACERA 1020 firmware versions 01.86 and earlier, update to a version later than 01.86.
For FURUNO SYSTEMS ACERA 1010 firmware versions 01.86 and earlier, update to a version later than 01.86.
For FURUNO SYSTEMS ACERA 950 firmware versions 01.60 and earlier, update to a version later than 01.60.
For FURUNO SYSTEMS ACERA 850F firmware versions 01.60 and earlier, update to a version later than 01.60.
For FURUNO SYSTEMS ACERA 900 firmware versions 02.54 and earlier, update to a version later than 02.54.
For FURUNO SYSTEMS ACERA 850M firmware versions 02.06 and earlier, update to a version later than 02.06.
For FURUNO SYSTEMS ACERA 810 firmware versions 03.74 and earlier, update to a version later than 03.74.
For FURUNO SYSTEMS ACERA 800ST firmware versions 07.35 and earlier, update to a version later than 07.35.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acera 1010
Acera 1020
Acera 1110
Acera 1150I
Acera 1150W
Acera 1210
Acera 800St
Acera 810
Acera 850F
Acera 850M
Acera 900
Acera 950