First published: Fri Jun 30 2017(Updated: )
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless Airlink Raven Xe Firmware | <=- | |
Sierra Wireless AirLink Raven XE | ||
Sierra Wireless Airlink Raven Xt Firmware | ||
Sierra Wireless Airlink Raven Xt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6042 is a moderate severity vulnerability due to its potential exploitation via Cross-Site Request Forgery.
To fix CVE-2017-6042, update the Sierra Wireless AirLink Raven XE to version 4.0.14 or later, or the AirLink Raven XT to version 4.0.11 or later.
CVE-2017-6042 affects Sierra Wireless AirLink Raven XE and AirLink Raven XT devices running versions prior to 4.0.14 and 4.0.11, respectively.
CVE-2017-6042 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2017-6042 can be exploited remotely by tricking a user into making unintended requests.