Authentication bypass in SkyRouter Series 4400 and SkyRouter Series 4200 - CVE-2017-14000
Published: September 22, 2017
Vulnerability identifier: #VU8573
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14000
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication on the target system.
The weakness exists due to improper authentication. A remote attacker can access a specific uniform resource locator (URL) on the web server and bypass authentication to view and edit settings.
The weakness exists due to improper authentication. A remote attacker can access a specific uniform resource locator (URL) on the web server and bypass authentication to view and edit settings.
Affected software
SkyRouter Series 4400
SkyRouter Series 4200
SkyRouter Series 4200
How to mitigate CVE-2017-14000
Update to version 6.00.11.