vendor:
OmniSwitch 6450
by:
RedTeam Pentesting
5.5
CVSS
MEDIUM
Cross-site request forgery
352
CWE
Product Name: OmniSwitch 6450
Affected Version From: AOS 6.4.5.R02
Affected Version To: AOS 8.1.1.R01
Patch Exists: NO
Related CWE: CVE-2015-2805
CPE: h:alcatel-lucent:omnswitch_6450
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Gigabit and Fast Ethernet Stackable LAN Switches
2015
Advisory: Alcatel-Lucent OmniSwitch Web Interface Cross-Site Request Forgery
During a penetration test, RedTeam Pentesting discovered a vulnerability in the management web interface of an Alcatel-Lucent OmniSwitch 6450. The management web interface has no protection against cross-site request forgery attacks. This allows specially crafted web pages to change the switch configuration and create users, if an administrator accesses the website while being authenticated in the management web interface.
Mitigation:
The vendor has been notified and is currently working on a patch.