Vulnerability CVE-2017-7909


Published: 2017-05-05   Modified: 2017-05-06

Description:
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Advantech b+b smartworx -> Mesr901 firmware 

 References:
http://www.securityfocus.com/bid/98257
https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03

Copyright 2024, cxsecurity.com

 

Back to Top