Vulnerability Description
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arcadyan | Swisscom Internet-Box Firmware | - |
| Arcadyan | Swisscom Internet-Box | - |
Related Weaknesses (CWE)
References
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-scVendor Advisory
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-scVendor Advisory
FAQ
What is CVE-2016-10042?
CVE-2016-10042 is a vulnerability with a CVSS score of 7.5 (HIGH). Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticate...
How severe is CVE-2016-10042?
CVE-2016-10042 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10042?
Check the references section above for vendor advisories and patch information. Affected products include: Arcadyan Swisscom Internet-Box Firmware, Arcadyan Swisscom Internet-Box.