Lucene search

K
cve[email protected]CVE-2011-1324
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-1324

2022-10-0316:15:11
CWE-352
web.nvd.nist.gov
25
cve-2011-1324
cross-site request forgery
csrf
buffalo
routers
firmware vulnerability
remote authentication hijacking

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.2%

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.

Affected configurations

NVD
Node
buffalotechbbr-4hg_firmwareMatch1.02
OR
buffalotechbbr-4hg_firmwareMatch1.04
OR
buffalotechbbr-4hg_firmwareMatch1.04beta
OR
buffalotechbbr-4hg_firmwareMatch1.10
OR
buffalotechbbr-4hg_firmwareMatch1.10beta
OR
buffalotechbbr-4hg_firmwareMatch1.11beta
OR
buffalotechbbr-4hg_firmwareMatch1.12
OR
buffalotechbbr-4hg_firmwareMatch1.20
OR
buffalotechbbr-4hg_firmwareMatch1.20beta
OR
buffalotechbbr-4hg_firmwareMatch1.30
OR
buffalotechbbr-4hg_firmwareMatch1.30beta
OR
buffalotechbbr-4hg_firmwareMatch1.31
OR
buffalotechbbr-4hg_firmwareMatch1.32
OR
buffalotechbbr-4hg_firmwareMatch1.32beta
OR
buffalotechbbr-4hg_firmwareMatch1.33beta
OR
buffalotechbbr-4mg_firmwareMatch1.00
OR
buffalotechbbr-4mg_firmwareMatch1.01beta
OR
buffalotechbbr-4mg_firmwareMatch1.03
OR
buffalotechbbr-4mg_firmwareMatch1.04
OR
buffalotechbbr-4mg_firmwareMatch1.04beta
OR
buffalotechbbr-4mg_firmwareMatch1.10
OR
buffalotechbbr-4mg_firmwareMatch1.10beta
OR
buffalotechbbr-4mg_firmwareMatch1.11beta
OR
buffalotechbbr-4mg_firmwareMatch1.12
OR
buffalotechbbr-4mg_firmwareMatch1.20
OR
buffalotechbbr-4mg_firmwareMatch1.20beta
OR
buffalotechbbr-4mg_firmwareMatch1.30
OR
buffalotechbbr-4mg_firmwareMatch1.30beta
OR
buffalotechbbr-4mg_firmwareMatch1.31
OR
buffalotechbbr-4mg_firmwareMatch1.32
OR
buffalotechbbr-4mg_firmwareMatch1.32beta
OR
buffalotechbbr-4mg_firmwareMatch1.33
OR
buffalotechbbr-4mg_firmwareMatch1.33beta
OR
buffalotechbhr-4rv_firmwareMatch2.31
OR
buffalotechbhr-4rv_firmwareMatch2.32prebeta
OR
buffalotechbhr-4rv_firmwareMatch2.33prebeta
OR
buffalotechbhr-4rv_firmwareMatch2.42
OR
buffalotechbhr-4rv_firmwareMatch2.46
OR
buffalotechbhr-4rv_firmwareMatch2.48
OR
buffalotechfs-g54_firmwareMatch2.07
OR
buffalotechwer-a54g54_firmwareMatch1.00
OR
buffalotechwer-a54g54_firmwareMatch1.01beta
OR
buffalotechwer-a54g54_firmwareMatch1.02
OR
buffalotechwer-a54g54_firmwareMatch1.03
OR
buffalotechwer-a54g54_firmwareMatch1.10
OR
buffalotechwer-a54g54_firmwareMatch1.12
OR
buffalotechwer-a54g54_firmwareMatch1.12beta
OR
buffalotechwer-a54g54_firmwareMatch1.13
OR
buffalotechwer-ag54_firmwareMatch1.04
OR
buffalotechwer-ag54_firmwareMatch1.12
OR
buffalotechwer-ag54_firmwareMatch1.12beta
OR
buffalotechwer-am54g54_firmwareMatch1.11
OR
buffalotechwer-am54g54_firmwareMatch1.12
OR
buffalotechwer-am54g54_firmwareMatch1.12beta
OR
buffalotechwer-am54g54_firmwareMatch1.13
OR
buffalotechwer-am54g54_firmwareMatch1.14
OR
buffalotechwer-amg54_firmwareMatch1.11
OR
buffalotechwer-amg54_firmwareMatch1.12
OR
buffalotechwer-amg54_firmwareMatch1.14
OR
buffalotechwhr-am54g54_firmwareMatch1.30
OR
buffalotechwhr-am54g54_firmwareMatch1.38
OR
buffalotechwhr-am54g54_firmwareMatch1.40
OR
buffalotechwhr-am54g54_firmwareMatch1.42
OR
buffalotechwhr-amg54_firmwareMatch1.31
OR
buffalotechwhr-amg54_firmwareMatch1.38
OR
buffalotechwhr-amg54_firmwareMatch1.40
OR
buffalotechwhr-amg54_firmwareMatch1.42
OR
buffalotechwhr-ampg_firmwareMatch1.46
OR
buffalotechwhr-g_firmwareMatch1.46
OR
buffalotechwhr-g54s_firmwareMatch1.20
OR
buffalotechwhr-g54s_firmwareMatch1.21
OR
buffalotechwhr-g54s_firmwareMatch1.23
OR
buffalotechwhr-g54s_firmwareMatch1.38
OR
buffalotechwhr-g54s_firmwareMatch1.40
OR
buffalotechwhr-g54s_firmwareMatch1.42
OR
buffalotechwhr-hp-ampg_firmwareMatch1.32
OR
buffalotechwhr-hp-g_firmwareMatch1.46
OR
buffalotechwhr-hp-g54_firmwareMatch1.20
OR
buffalotechwhr-hp-g54_firmwareMatch1.21
OR
buffalotechwhr-hp-g54_firmwareMatch1.23
OR
buffalotechwhr-hp-g54_firmwareMatch1.38
OR
buffalotechwhr-hp-g54_firmwareMatch1.40
OR
buffalotechwhr-hp-g54_firmwareMatch1.42
OR
buffalotechwzr-ampg144nh_firmwareMatch1.47
OR
buffalotechwzr-ampg144nh_firmwareMatch1.48beta
OR
buffalotechwzr-ampg300nh_firmwareMatch1.48
OR
buffalotechwzr-g144n_firmwareMatch1.45
OR
buffalotechwzr-g144n_firmwareMatch1.46beta
OR
buffalotechwzr-g144n_firmwareMatch1.47
OR
buffalotechwzr-g144n_firmwareMatch1.47beta
OR
buffalotechwzr-g144nh_firmwareMatch1.45
OR
buffalotechwzr-g144nh_firmwareMatch1.47
OR
buffalotechwzr-g144nh_firmwareMatch1.47beta
OR
buffalotechwzr-g144nh_firmwareMatch1.48
OR
buffalotechwzr2-g300n_firmwareMatch1.48
OR
buffalotechwzr2-g300n_firmwareMatch1.50beta
OR
buffalotechas-100
OR
buffalotechbbr-4hg
OR
buffalotechbbr-4mg
OR
buffalotechbhr-4rv
OR
buffalotechfs-g54
OR
buffalotechwer-a54g54
OR
buffalotechwer-ag54
OR
buffalotechwer-am54g54
OR
buffalotechwer-amg54
OR
buffalotechwhr-am54g54
OR
buffalotechwhr-amg54
OR
buffalotechwhr-ampg
OR
buffalotechwhr-g
OR
buffalotechwhr-g54s
OR
buffalotechwhr-hp-ampg
OR
buffalotechwhr-hp-g
OR
buffalotechwhr-hp-g54
OR
buffalotechwzr-ampg144nh
OR
buffalotechwzr-ampg300nh
OR
buffalotechwzr-g144n
OR
buffalotechwzr-g144nh
OR
buffalotechwzr2-g300n

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.2%

Related for CVE-2011-1324