CVE-2017-8334

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:securifi:almond_2015_firmware:al-r096:*:*:*:*:*:*:*
cpe:2.3:h:securifi:almond_2015:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:securifi:almond\+firmware:al-r096:*:*:*:*:*:*:*
cpe:2.3:h:securifi:almond\+:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:securifi:almond_firmware:al-r096:*:*:*:*:*:*:*
cpe:2.3:h:securifi:almond:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-06-18 21:15

Updated : 2024-02-04 20:20


NVD link : CVE-2017-8334

Mitre link : CVE-2017-8334

CVE.ORG link : CVE-2017-8334


JSON object : View

Products Affected

securifi

  • almond_2015_firmware
  • almond\+firmware
  • almond
  • almond_firmware
  • almond\+
  • almond_2015
CWE
CWE-352

Cross-Site Request Forgery (CSRF)