Описание
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.
Ссылки
- ExploitTechnical DescriptionThird Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.2 (исключая)
Одновременно
cpe:2.3:o:impinj:r420_rfid_reader_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:impinj:r420_rfid_reader:-:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00259
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.
EPSS
Процентиль: 49%
0.00259
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-601