search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Silver Peak VX is vulnerable to cross-site request forgery and cross-site scripting

Vulnerability Note VU#867980

Original Release Date: 2014-07-28 | Last Revised: 2014-07-28

Overview

Silver Peak VX version 6.2.2.0_47968 is vulnerable to cross-site request forgery and cross-site scripting.

Description

CWE-352: Cross-Site Request Forgery (CSRF) - CVE-2014-2974

Silver Peak VX version 6.2.2.0_47968 contains a cross-site request forgery vulnerability in /php/user_account.php that allows an unauthenticated user to create a new administrator account.

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2014-2975
Silver Peak VX version 6.2.2.0_47968 also contains a reflected cross-site scripting vulnerability in /php/user_account.php that can allow an attacker to inject arbitrary HTML content (including scripts) via the vulnerable query string parameter user_id .

The CVSS score below applies to the CVE-2013-2975 vulnerability.

Impact

An attacker can conduct a cross-site scripting or cross-site request forgery attack, which could be used for privilege escalation or to inject arbitrary HTML content (including script) into a web page presented to the user.

Solution

Apply an Update
Silver Peak has provided an update to fix CVE-2014-2975 in Silver Peak VX 6.2.4. CVE-2014-2974 is expected to be addressed "in the next maintenance release" according to the vendor.

Vendor Information

867980
 
Affected   Unknown   Unaffected

Silver Peak

Notified:  April 16, 2014 Updated:  July 23, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 5.0 AV:N/AC:L/Au:N/C:N/I:P/A:N
Temporal 4.0 E:POC/RL:TF/RC:C
Environmental 0 CDP:N/TD:N/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to William Costa for reporting this vulnerability.

This document was written by Chris King.

Other Information

CVE IDs: CVE-2014-2974, CVE-2014-2975
Date Public: 2014-07-28
Date First Published: 2014-07-28
Date Last Updated: 2014-07-28 13:06 UTC
Document Revision: 17

Sponsored by the Department of Homeland Security Office of Cybersecurity and Communications.