Lucene search

K
cveMitreCVE-2017-9390
HistoryJun 17, 2019 - 8:15 p.m.

CVE-2017-9390

2019-06-1720:15:09
CWE-79
mitre
web.nvd.nist.gov
47
cve-2017-9390
information security
code execution
vera veraedge
veralite
input validation
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.004

Percentile

73.0%

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the user is authenticated to https://home.getvera.com. One of the parameters retrieved by this script is “RedirectURL”. However, the application lacks strict input validation of this parameter and this allows an attacker to execute the client-side code on this application.

Affected configurations

Nvd
Node
getveraveraedgeMatch-
AND
getveraveraedge_firmwareRange1.7.19
Node
getveraveraliteMatch-
AND
getveraveralite_firmwareRange1.7.481
VendorProductVersionCPE
getveraveraedge-cpe:2.3:h:getvera:veraedge:-:*:*:*:*:*:*:*
getveraveraedge_firmware*cpe:2.3:o:getvera:veraedge_firmware:*:*:*:*:*:*:*:*
getveraveralite-cpe:2.3:h:getvera:veralite:-:*:*:*:*:*:*:*
getveraveralite_firmware*cpe:2.3:o:getvera:veralite_firmware:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.004

Percentile

73.0%

Related for CVE-2017-9390