« Volver al listado

CVE-2013-0717

Estado: ModificadaMedia (6.8)—

Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-0717",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-19T18:55:03.347",
  "references": [
    {
      "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN59503133/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jpn.nec.com/security-info/secinfo/nv13-005.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN59503133/6443/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN59503133/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades CSRF en la utilidad de gestión web de los enrutadores NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, y AtermWM3450RN, permite a los atacantes remotos secuestrar la autenticación de los administradores para peticiones que (1)inicializan opciones o (2) reinician el dispositivo."
    }
  ],
  "lastModified": "2026-06-16T23:49:56.810",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:nec:atermwm3450rn:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2214321D-ABC8-4FFD-BF33-E1F707386DD5"
            },
            {
              "criteria": "cpe:2.3:h:nec:atermwm3600r:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D5040C6-5035-46CF-A80C-E2D69A5E3401"
            },
            {
              "criteria": "cpe:2.3:h:nec:atermwr8160n:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36D01D2D-ABD8-47C7-8070-41608AE59DE8"
            },
            {
              "criteria": "cpe:2.3:h:nec:atermwr8370n:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20AB6685-5F0E-46E9-8776-2FBF8ACE8DF4"
            },
            {
              "criteria": "cpe:2.3:h:nec:atermwr8600n:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56589FA6-6A4E-4D47-83BE-9E246E722202"
            },
            {
              "criteria": "cpe:2.3:h:nec:atermwr9500n:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC88A006-8AB5-4780-8280-676B34BFE7F4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}