CVE-2018-4066: CSRF
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4066?
CVE-2018-4066 is a cross-site request forgery vulnerability in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
What is the severity of CVE-2018-4066?
CVE-2018-4066 has a severity rating of 8.8 (High).
What is the affected software?
The Sierra Wireless AirLink ES450 FW 4.9.3 is affected by CVE-2018-4066.
How can CVE-2018-4066 be exploited?
CVE-2018-4066 can be exploited through a specially crafted HTTP request that can cause an authenticated user to perform privileged requests unknowingly.
Are there any references related to CVE-2018-4066?
Yes, you can find more information about CVE-2018-4066 at the following references: [1] http://packetstormsecurity.com/files/152651/Sierra-Wireless-AirLink-ES450-ACEManager-Cross-Site-Request-Forgery.html [2] http://www.securityfocus.com/bid/108147 [3] https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03