First published: Thu Jun 29 2017(Updated: )
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arcadyan Swisscom Internet-box Firmware | ||
Arcadyan Swisscom Internet-box | ||
Arcadyan Swisscom Internet-box | ||
Arcadyan Swisscom Internet-box |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10042 is considered a critical vulnerability due to its potential for unauthorized device reconfiguration and associated denial of service.
To fix CVE-2016-10042, update the Arcadyan Swisscom Internet-Box firmware to version R7.7 or later.
CVE-2016-10042 affects Arcadyan SLT-00 Star* (Swisscom Internet-Box) devices with firmware versions prior to R7.7.
The potential impacts of CVE-2016-10042 include unauthorized access to static routing configurations, leading to information disclosure and denial of service.
Yes, CVE-2016-10042 can be exploited remotely via unauthenticated HTTP requests to the vulnerable devices.