CVE-2011-1324

CVSS V2 Medium 5.8 CVSS V3 None
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
Overview
  • CVE ID
  • CVE-2011-1324
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2011-05-09T19:55:03
  • Last Modified Date
  • 2011-05-27T04:00:00
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.02:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.04:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.04:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.10:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.11:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.20:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.30:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.32:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4hg_firmware:1.33:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.00:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.01:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.03:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.04:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.04:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.10:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.11:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.20:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.30:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.32:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.33:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bbr-4mg_firmware:1.33:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.32:prebeta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.33:prebeta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:bhr-4rv_firmware:2.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:fs-g54_firmware:2.07:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.00:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.01:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.02:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.03:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.12:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-a54g54_firmware:1.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-ag54_firmware:1.04:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-ag54_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-ag54_firmware:1.12:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-am54g54_firmware:1.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-am54g54_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-am54g54_firmware:1.12:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-am54g54_firmware:1.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-am54g54_firmware:1.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-amg54_firmware:1.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-amg54_firmware:1.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wer-amg54_firmware:1.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-am54g54_firmware:1.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-am54g54_firmware:1.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-am54g54_firmware:1.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-am54g54_firmware:1.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-amg54_firmware:1.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-amg54_firmware:1.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-amg54_firmware:1.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-amg54_firmware:1.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-ampg_firmware:1.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g_firmware:1.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.23:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-g54s_firmware:1.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-ampg_firmware:1.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g_firmware:1.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.23:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:whr-hp-g54_firmware:1.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-ampg144nh_firmware:1.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-ampg144nh_firmware:1.48:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-ampg300nh_firmware:1.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144n_firmware:1.45:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144n_firmware:1.46:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144n_firmware:1.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144n_firmware:1.47:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144nh_firmware:1.45:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144nh_firmware:1.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144nh_firmware:1.47:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr-g144nh_firmware:1.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr2-g300n_firmware:1.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:buffalotech:wzr2-g300n_firmware:1.50:beta:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:as-100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:bbr-4hg:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:bbr-4mg:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:bhr-4rv:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:fs-g54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wer-a54g54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wer-ag54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wer-am54g54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wer-amg54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-am54g54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-amg54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-ampg:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-g:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-g54s:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-hp-ampg:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-hp-g:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:whr-hp-g54:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wzr-ampg144nh:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wzr-ampg300nh:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wzr-g144n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wzr-g144nh:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:buffalotech:wzr2-g300n:*:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 4.9
History
Created Old Value New Value Data Type Notes
2022-05-10 11:00:20 Added to TrackCVE