Lucene search

K
cveMitreCVE-2011-0886
HistoryFeb 08, 2011 - 10:00 p.m.

CVE-2011-0886

2011-02-0822:00:02
CWE-352
mitre
web.nvd.nist.gov
23
cve-2011-0886
csrf
smc smcd3g-ccr
comcast business gateway
firmware
remote attackers
intranet connectivity
authentication
dns settings

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.016

Percentile

87.8%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 allow remote attackers to (1) hijack the intranet connectivity of arbitrary users for requests that perform a login via goform/login, or hijack the authentication of administrators for requests that (2) enable external logins via an mso_remote_enable action to goform/RemoteRange or (3) change DNS settings via a manual_dns_enable action to goform/Basic.

Affected configurations

Nvd
Node
smc_networkssmcd3g-ccr
AND
smc_networkssmcd3g-ccr_firmwareRange1.4.0.49
OR
smc_networkssmcd3g-ccr_firmwareMatch1.4.0.42
VendorProductVersionCPE
smc_networkssmcd3g-ccr*cpe:2.3:h:smc_networks:smcd3g-ccr:*:*:*:*:*:*:*:*
smc_networkssmcd3g-ccr_firmware*cpe:2.3:a:smc_networks:smcd3g-ccr_firmware:*:*:*:*:*:*:*:*
smc_networkssmcd3g-ccr_firmware1.4.0.42cpe:2.3:a:smc_networks:smcd3g-ccr_firmware:1.4.0.42:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.016

Percentile

87.8%