Vulnerabilites related to nec - atermwm3600r
CVE-2013-0717 (GCVE-0-2013-0717)
Vulnerability from cvelistv5
Published
2013-03-19 18:00
Modified
2024-09-17 02:51
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.
References
► | URL | Tags | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T14:33:05.603Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html" }, { "name": "JVNDB-2013-000024", "tags": [ "third-party-advisory", "x_refsource_JVNDB", "x_transferred" ], "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html" }, { "name": "JVN#59503133", "tags": [ "third-party-advisory", "x_refsource_JVN", "x_transferred" ], "url": "http://jvn.jp/en/jp/JVN59503133/index.html" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "descriptions": [ { "lang": "en", "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2013-03-19T18:00:00Z", "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html" }, { "name": "JVNDB-2013-000024", "tags": [ "third-party-advisory", "x_refsource_JVNDB" ], "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html" }, { "name": "JVN#59503133", "tags": [ "third-party-advisory", "x_refsource_JVN" ], "url": "http://jvn.jp/en/jp/JVN59503133/index.html" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "vultures@jpcert.or.jp", "ID": "CVE-2013-0717", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://jvn.jp/en/jp/JVN59503133/6443/index.html", "refsource": "CONFIRM", "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html" }, { "name": "JVNDB-2013-000024", "refsource": "JVNDB", "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024" }, { "name": "http://jpn.nec.com/security-info/secinfo/nv13-005.html", "refsource": "CONFIRM", "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html" }, { "name": "JVN#59503133", "refsource": "JVN", "url": "http://jvn.jp/en/jp/JVN59503133/index.html" } ] } } } }, "cveMetadata": { "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "assignerShortName": "jpcert", "cveId": "CVE-2013-0717", "datePublished": "2013-03-19T18:00:00Z", "dateReserved": "2012-12-28T00:00:00Z", "dateUpdated": "2024-09-17T02:51:50.999Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Vulnerability from fkie_nvd
Published
2013-03-19 18:55
Modified
2025-04-11 00:51
Severity ?
Summary
Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
nec | atermwm3450rn | - | |
nec | atermwm3600r | - | |
nec | atermwr8160n | - | |
nec | atermwr8370n | - | |
nec | atermwr8600n | - | |
nec | atermwr9500n | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:h:nec:atermwm3450rn:-:*:*:*:*:*:*:*", "matchCriteriaId": "2214321D-ABC8-4FFD-BF33-E1F707386DD5", "vulnerable": true }, { "criteria": "cpe:2.3:h:nec:atermwm3600r:-:*:*:*:*:*:*:*", "matchCriteriaId": "6D5040C6-5035-46CF-A80C-E2D69A5E3401", "vulnerable": true }, { "criteria": "cpe:2.3:h:nec:atermwr8160n:-:*:*:*:*:*:*:*", "matchCriteriaId": "36D01D2D-ABD8-47C7-8070-41608AE59DE8", "vulnerable": true }, { "criteria": "cpe:2.3:h:nec:atermwr8370n:-:*:*:*:*:*:*:*", "matchCriteriaId": "20AB6685-5F0E-46E9-8776-2FBF8ACE8DF4", "vulnerable": true }, { "criteria": "cpe:2.3:h:nec:atermwr8600n:-:*:*:*:*:*:*:*", "matchCriteriaId": "56589FA6-6A4E-4D47-83BE-9E246E722202", "vulnerable": true }, { "criteria": "cpe:2.3:h:nec:atermwr9500n:-:*:*:*:*:*:*:*", "matchCriteriaId": "EC88A006-8AB5-4780-8280-676B34BFE7F4", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades CSRF en la utilidad de gesti\u00f3n web de los enrutadores NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, y AtermWM3450RN, permite a los atacantes remotos secuestrar la autenticaci\u00f3n de los administradores para peticiones que (1)inicializan opciones o (2) reinician el dispositivo." } ], "id": "CVE-2013-0717", "lastModified": "2025-04-11T00:51:21.963", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ] }, "published": "2013-03-19T18:55:03.347", "references": [ { "source": "vultures@jpcert.or.jp", "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html" }, { "source": "vultures@jpcert.or.jp", "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html" }, { "source": "vultures@jpcert.or.jp", "url": "http://jvn.jp/en/jp/JVN59503133/index.html" }, { "source": "vultures@jpcert.or.jp", "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://jvn.jp/en/jp/JVN59503133/index.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024" } ], "sourceIdentifier": "vultures@jpcert.or.jp", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-352" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }