Cross-Site Request Forgery Vulnerability in Sierra Wireless AirLink Devices
CVE-2017-6042

8.8HIGH

Key Information:

Vendor
CVE Published:
30 June 2017

What is CVE-2017-6042?

A Cross-Site Request Forgery (CSRF) vulnerability exists in Sierra Wireless AirLink Raven XE and Raven XT devices, where the system fails to verify if incoming requests are legitimate and initiated by the authenticated user. This flaw enables an attacker to exploit the device by tricking a logged-in user into executing unintended requests, potentially leading to unauthorized actions on the web server without the user's knowledge. Users are encouraged to update to the latest firmware versions to mitigate this risk.

Affected Version(s)

Sierra Wireless AirLink Raven XE and XT Sierra Wireless AirLink Raven XE and XT

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.