ID

VAR-201510-0774


TITLE

Multiple routers contain issue in preventing clickjacking attacks

Trust: 0.8

sources: JVNDB: JVNDB-2015-000172

DESCRIPTION

Multiple router products contain an issue in the protection against clickjacking attacks. Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.If a user views a malicious page while logged in, unintended operations may be conducted. Multiple Routers are prone to a clickjacking vulnerability because it fails to perform validity checks on certain user actions through HTTP requests. Successful exploits will allow an attacker to compromise the affected device or obtain sensitive information. Other attacks are also possible

Trust: 0.99

sources: JVNDB: JVNDB-2015-000172 // BID: 77386

AFFECTED PRODUCTS

vendor:multiple vendersmodel: - scope: - version: -

Trust: 0.8

vendor:yamahamodel:srt100scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rtx810scope:eqversion:11.1.21

Trust: 0.3

vendor:yamahamodel:rtx1500scope: - version: -

Trust: 0.3

vendor:yamahamodel:rtx1210scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rtx1200scope:eqversion:10.1.59

Trust: 0.3

vendor:yamahamodel:rtv01scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rt58iscope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rt107escope:eqversion:0

Trust: 0.3

vendor:yamahamodel:nvr500scope:eqversion:11.0.25

Trust: 0.3

vendor:yamahamodel:fwx120scope:eqversion:11.3.8

Trust: 0.3

vendor:necmodel:infocagescope:eqversion:3.1

Trust: 0.3

vendor:yamahamodel:rtx810scope:neversion:11.1.25

Trust: 0.3

vendor:yamahamodel:rtx1200scope:neversion:10.1.65

Trust: 0.3

vendor:yamahamodel:nvr500scope:neversion:11.0.28

Trust: 0.3

vendor:yamahamodel:fwx120scope:neversion:11.3.13

Trust: 0.3

vendor:necmodel:infocagescope:neversion:5.1

Trust: 0.3

sources: BID: 77386 // JVNDB: JVNDB-2015-000172

CVSS

SEVERITY

CVSSV2

CVSSV3

IPA: JVNDB-2015-000172
value: LOW

Trust: 0.8

IPA: JVNDB-2015-000172
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

sources: JVNDB: JVNDB-2015-000172

PROBLEMTYPE DATA

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2015-000172

THREAT TYPE

network

Trust: 0.3

sources: BID: 77386

TYPE

Design Error

Trust: 0.3

sources: BID: 77386

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-000172

PATCH

title:Yamaha Corporation websiteurl:http://www.rtpro.yamaha.co.jp/rt/faq/security/jvn48135658.html

Trust: 0.8

title:vulnera_20151127url:http://www.furukawa.co.jp/fitelnet/topic/vulnera_20151127.html

Trust: 0.8

title:Information from Allied Telesisurl:https://jvn.jp/jp/jvn48135658/522154/index.html

Trust: 0.8

title:NV15-019url:http://jpn.nec.com/security-info/secinfo/nv15-019.html

Trust: 0.8

title: PLANEX COMMUNICATIONS INC. website url:http://www.planex.co.jp/news/info/20151030_info.shtml

Trust: 0.8

title:I-O DATA DEVICE, INC. websiteurl:http://www.iodata.jp/support/information/2016/clickjacking/

Trust: 0.8

sources: JVNDB: JVNDB-2015-000172

EXTERNAL IDS

db:JVNid:JVN48135658

Trust: 1.1

db:JVNDBid:JVNDB-2015-000172

Trust: 0.8

db:BIDid:77386

Trust: 0.3

sources: BID: 77386 // JVNDB: JVNDB-2015-000172

REFERENCES

url:http://jvn.jp/en/jp/jvn48135658/index.html

Trust: 1.1

url:http://www.rtpro.yamaha.co.jp/rt/faq/security/jvn48135658.html

Trust: 0.3

url:http://jpn.nec.com/security-info/secinfo/nv15-019.html

Trust: 0.3

sources: BID: 77386 // JVNDB: JVNDB-2015-000172

CREDITS

Noriaki Iwasaki of Cyber Defense Institute

Trust: 0.3

sources: BID: 77386

SOURCES

db:BIDid:77386
db:JVNDBid:JVNDB-2015-000172

LAST UPDATE DATE

2022-05-17T02:02:28.205000+00:00


SOURCES UPDATE DATE

db:BIDid:77386date:2015-10-30T00:00:00
db:JVNDBid:JVNDB-2015-000172date:2016-02-12T00:00:00

SOURCES RELEASE DATE

db:BIDid:77386date:2015-10-30T00:00:00
db:JVNDBid:JVNDB-2015-000172date:2015-10-30T00:00:00