CVE-2024-1890: Clickjacking vulnerability in Sunny Webbox
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sunny Webboxto a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1890?
CVE-2024-1890 is considered a medium severity vulnerability due to its potential for clickjacking attacks on affected devices.
How do I fix CVE-2024-1890?
To mitigate CVE-2024-1890, upgrade to Sunny WebBox firmware version 1.6.2 or later, which contains the necessary security fixes.
What systems are affected by CVE-2024-1890?
CVE-2024-1890 affects Sunny WebBox firmware versions 1.6.1 and earlier.
What type of attack can be executed through CVE-2024-1890?
CVE-2024-1890 allows attackers to perform clickjacking attacks by tricking authenticated users into clicking malicious links.
Is authentication required to exploit CVE-2024-1890?
Yes, CVE-2024-1890 requires an authenticated operator to be targeted for the clickjacking attack to be successful.