Vulnerability Description
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Impinj | R420 Rfid Reader Firmware | < 2.2.2 |
| Impinj | R420 Rfid Reader | - |
Related Weaknesses (CWE)
References
- http://blog.isecurion.com/2018/05/09/impinj-speedway-r420-rfid-reader/ExploitTechnical DescriptionThird Party Advisory
- http://blog.isecurion.com/2018/05/09/impinj-speedway-r420-rfid-reader/ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-5304?
CVE-2018-5304 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web applic...
How severe is CVE-2018-5304?
CVE-2018-5304 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5304?
Check the references section above for vendor advisories and patch information. Affected products include: Impinj R420 Rfid Reader Firmware, Impinj R420 Rfid Reader.