RSS   Vulnerabilities for
'Gecko lite managed switch firmware'
   RSS

2017-06-29
 
CVE-2017-6040

CWE-200
 

 
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.

 
 
CVE-2017-6038

CWE-352
 

 
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.

 
 
CVE-2017-6036

CWE-918
 

 
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently verify that the request is being sent to the expected destination.

 
2017-02-13
 
CVE-2017-5163

 

 
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a location that is accessible without authentication by path traversal.

 


Copyright 2024, cxsecurity.com

 

Back to Top