CVE-2017-6042: CSRF
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6042?
CVE-2017-6042 is a moderate severity vulnerability due to its potential exploitation via Cross-Site Request Forgery.
How do I fix CVE-2017-6042?
To fix CVE-2017-6042, update the Sierra Wireless AirLink Raven XE to version 4.0.14 or later, or the AirLink Raven XT to version 4.0.11 or later.
What devices are affected by CVE-2017-6042?
CVE-2017-6042 affects Sierra Wireless AirLink Raven XE and AirLink Raven XT devices running versions prior to 4.0.14 and 4.0.11, respectively.
What type of vulnerability is CVE-2017-6042?
CVE-2017-6042 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2017-6042 be exploited remotely?
Yes, CVE-2017-6042 can be exploited remotely by tricking a user into making unintended requests.