First published: Wed Jun 06 2018(Updated: )
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Beronet Voice Over Internet Protocol Gateways Firmware | <=3.39 | |
ABB IP Gateway Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7906 has a high severity rating due to its potential for unauthorized request impersonation.
To address CVE-2017-7906, upgrade the ABB IP Gateway firmware to version 3.40 or later.
CVE-2017-7906 affects ABB IP Gateway firmware versions 3.39 and earlier.
Exploiting CVE-2017-7906 allows attackers to perform actions as an authenticated user without their knowledge.
Currently, the recommended approach for CVE-2017-7906 is to upgrade the firmware rather than relying on a workaround.