CRLF Injection Vulnerability in Infoblox Network Automation
CVE-2016-6484

6.1MEDIUM

Key Information:

Vendor

Infoblox

Status
Vendor
CVE Published:
23 January 2017

What is CVE-2016-6484?

The CRLF injection vulnerability in Infoblox Network Automation NetMRI prior to version 7.1.1 allows remote attackers to manipulate HTTP headers. By exploiting the contentType parameter during the login process at config/userAdmin/login.tdf, attackers can execute HTTP response splitting attacks. This enables potential data breaches or unauthorized actions on affected systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.