CVE-2019-13529
Summary
| CVE | CVE-2019-13529 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-09 16:15:00 UTC |
| Updated | 2019-10-15 16:54:00 UTC |
| Description | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sma | Sunny Webbox | - | All | All | All |
| Hardware | Sma | Sunny Webbox | - | All | All | All |
| Operating System | Sma | Sunny Webbox Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SMA Solar Technology AG Sunny WebBox 1.6 Cross Site Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| SMA Solar Technology AG Sunny WebBox | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.