Back to search
CVE-2017-7909
Published: May 6, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.
| Vendor | Product | Versions |
|---|---|---|
n/a | Advantech B+B SmartWorx MESR901 | affected Advantech B+B SmartWorx MESR901 |
Weaknesses (CWE)
References
https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03
x_refsource_MISC
98257
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now