CVE-2019-17600: CSRF
Published Oct 15, 2019
·Updated
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
Affected Software
2 affected components
Intelbras Iwr 1000n Firmware=1.6.4
Intelbras IWR 1000N
Event History
Oct 15, 2019
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Intelbras IWR 1000N issue?
The vulnerability ID for this issue is CVE-2019-17600.
2
What is the severity of CVE-2019-17600?
The severity of CVE-2019-17600 is critical with a CVSS score of 9.8.
3
How does CVE-2019-17600 affect Intelbras IWR 1000N devices?
CVE-2019-17600 allows for the disclosure of the administrator login name and password on affected Intelbras IWR 1000N devices due to mishandling of the v1/system/user endpoint.
4
How can I check if my Intelbras IWR 1000N device is affected by CVE-2019-17600?
If you have an Intelbras IWR 1000N device with firmware version 1.6.4, it is affected by CVE-2019-17600.
5
Is there a fix available for CVE-2019-17600?
To fix CVE-2019-17600, Intelbras has released a firmware update that addresses the mishandling of the v1/system/user endpoint. Please update your device to the latest firmware version.