HIGH · 8.8

CVE-2017-8337

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of executing various actions on the web management in...

Vulnerability Description

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of executing various actions on the web management interface. It seems that the device does not implement any Origin header check which allows an attacker who can trick a user to navigate to an attacker's webpage to exploit this issue and brute force the password for the web management interface. It also allows an attacker to then execute any other actions which include management if rules, sensors attached to the devices using the websocket requests.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SecurifiAlmond 2015 Firmwareal-r096
SecurifiAlmond 2015-
SecurifiAlmond\+Firmwareal-r096
SecurifiAlmond\+-
SecurifiAlmond Firmwareal-r096
SecurifiAlmond-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-8337?

CVE-2017-8337 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of executing various actions on the web management in...

How severe is CVE-2017-8337?

CVE-2017-8337 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-8337?

Check the references section above for vendor advisories and patch information. Affected products include: Securifi Almond 2015 Firmware, Securifi Almond 2015, Securifi Almond\+Firmware, Securifi Almond\+, Securifi Almond Firmware.