| [Japanese] | 
| JVNDB-2017-000180 | 
| Multiple vulnerabilities in multiple Buffalo wireless LAN routers | 
|
| 
 
WMR-433 and WMR-433W provided by BUFFALO INC. are wireless LAN routers.  WMR-433 and WMR-433W contain multiple vulnerabilities listed below.
 * Cross-site Request Forgery (CWE-352) - CVE-2017-2273
 * Reflected Cross-site Scripting (CWE-79) - CVE-2017-2274
 
 Manabu Kobayashi reported this vulnerability to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 4.3 (Medium) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: RequiredScope: UnchangedConfidentiality Impact: NoneIntegrity Impact: NoneAvailability Impact: Low 
  CVSS V2 Severity:Base Metrics 4.3 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: NoneAvailability Impact: Partial 
  
The above CVSS base scores have been assigned for CVE-2017-2273.
 | 
| 
 
 CVSS V3 Severity:Base Metrics:
6.1 (Medium) [IPA Score]
 
Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: RequiredScope: ChangedConfidentiality Impact: LowIntegrity Impact: LowAvailability Impact: None CVSS V2 Severity:Base Metrics: 
4.3 (Medium) 
[IPA Score]
Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None
The above CVSS base scores have been assigned for CVE-2017-2274.
 | 
|
| 
 
	
 | 
| 
 
	BUFFALO INC.
	
		WMR-433 firmware Ver.1.02 and earlierWMR-433W firmware Ver.1.40 and earlier | 
| 
 
	
 | 
|
| 
 
The possible impact of each vulnerability is as follows:
 * If a logged-in user accesses a specially crafted page, configuration of the device may be changed or the device may be rebooted - CVE-2017-2273
 * If a logged-in user accesses a specially crafted page, an arbitrary script may be executed on the user's web browser - CVE-2017-2274
 | 
|
| 
 
[Update the Firmware]Apply the appropriate firmware update according to the information provided by the developer.
 | 
|
| 
 
	BUFFALO INC.
	
 | 
|
| 
 
	Cross-Site Request Forgery(CWE-352) [IPA Evaluation]Cross-site Scripting(CWE-79) [IPA Evaluation] | 
|
| 
 
	CVE-2017-2273 CVE-2017-2274  | 
|
| 
 
	JVN : JVN#48413726 National Vulnerability Database (NVD) : CVE-2017-2273 National Vulnerability Database (NVD) : CVE-2017-2274  | 
|
| 
 
	[2017/07/20]Web page was published
 [2018/01/24]
 References : Contents were added
 
 |