Authentication bypass in MESR901 - CVE-2017-7909
Published: May 4, 2017
Vulnerability identifier: #VU6419
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-7909
CWE-ID: CWE-603
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Advantech B+B SmartWorx
Affected software:
MESR901
MESR901
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to bypass authentication.
The weakness exists due to improper checking of client authentication and redirecting of unauthorized users by JavaScript. A remote attacker can intercept requests, bypass authentication and access restricted web pages.
Successful exploitation of this vulnerability results in access to the system.
The weakness exists due to improper checking of client authentication and redirecting of unauthorized users by JavaScript. A remote attacker can intercept requests, bypass authentication and access restricted web pages.
Successful exploitation of this vulnerability results in access to the system.
How to mitigate CVE-2017-7909
Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.