Description
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-15110 | A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request. |
References
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T15:18:49.761Z
Reserved: 2017-02-16T00:00:00.000Z
Link: CVE-2017-6042
No data.
Status : Modified
Published: 2017-06-30T03:29:00.593
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-6042
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD