First published: Tue Jan 28 2020(Updated: )
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VeraLite Firmware | =1.5.408 | |
Micasaverde VeraLite Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4865 is classified as a high severity vulnerability due to its potential for enabling remote attackers to hijack user authentication.
To resolve CVE-2013-4865, it is recommended to update the MiCasaVerde VeraLite firmware to a version that addresses the CSRF vulnerability.
CVE-2013-4865 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized actions on behalf of an authenticated user.
CVE-2013-4865 affects MiCasaVerde VeraLite devices running firmware version 1.5.408.
Yes, CVE-2013-4865 can allow attackers to install arbitrary firmware without users' consent due to insufficient validation in the upgrade process.