ID

VAR-201710-1295


CVE

CVE-2017-15304


TITLE

AIRTAME HDMI Dongle firmware vulnerable to session fixation

Trust: 0.8

sources: JVNDB: JVNDB-2017-009486

DESCRIPTION

/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin password change. AIRTAME HDMI Dongle firmware contains a session fixation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. AIRTAMEHDMIdongle is a wireless access point product for connecting, sharing and split-screen TVs or monitors. There is a security vulnerability in the /bin/login.php file of WebPanel in AirtameHDMIdongle with firmware version 3.0

Trust: 2.25

sources: NVD: CVE-2017-15304 // JVNDB: JVNDB-2017-009486 // CNVD: CNVD-2017-35541 // VULHUB: VHN-106113

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-35541

AFFECTED PRODUCTS

vendor:airtamemodel:hdmi donglescope:lteversion:2.3.3

Trust: 1.0

vendor:airtamemodel:hdmi donglescope:ltversion:3.0

Trust: 0.8

vendor:airtamemodel:hdmi donglescope:eqversion:3.0

Trust: 0.6

vendor:airtamemodel:hdmi donglescope:eqversion:2.3.3

Trust: 0.6

sources: CNVD: CNVD-2017-35541 // JVNDB: JVNDB-2017-009486 // CNNVD: CNNVD-201710-499 // NVD: CVE-2017-15304

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15304
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-15304
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-35541
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201710-499
value: HIGH

Trust: 0.6

VULHUB: VHN-106113
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-15304
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-35541
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-106113
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15304
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-35541 // VULHUB: VHN-106113 // JVNDB: JVNDB-2017-009486 // CNNVD: CNNVD-201710-499 // NVD: CVE-2017-15304

PROBLEMTYPE DATA

problemtype:CWE-384

Trust: 1.9

sources: VULHUB: VHN-106113 // JVNDB: JVNDB-2017-009486 // NVD: CVE-2017-15304

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201710-499

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201710-499

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009486

PATCH

title:Top Pageurl:https://airtame.com/

Trust: 0.8

sources: JVNDB: JVNDB-2017-009486

EXTERNAL IDS

db:NVDid:CVE-2017-15304

Trust: 3.1

db:JVNDBid:JVNDB-2017-009486

Trust: 0.8

db:CNNVDid:CNNVD-201710-499

Trust: 0.7

db:CNVDid:CNVD-2017-35541

Trust: 0.6

db:VULHUBid:VHN-106113

Trust: 0.1

sources: CNVD: CNVD-2017-35541 // VULHUB: VHN-106113 // JVNDB: JVNDB-2017-009486 // CNNVD: CNNVD-201710-499 // NVD: CVE-2017-15304

REFERENCES

url:https://www.utkusen.com/blog/multiple-vulnerabilities-on-airtame-device-before-version-3.html

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15304

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-15304

Trust: 0.8

url:https://utkusen.com/blog/multiple-vulnerabilities-on-airtame-device-before-version-3.html

Trust: 0.8

sources: CNVD: CNVD-2017-35541 // VULHUB: VHN-106113 // JVNDB: JVNDB-2017-009486 // CNNVD: CNNVD-201710-499 // NVD: CVE-2017-15304

SOURCES

db:CNVDid:CNVD-2017-35541
db:VULHUBid:VHN-106113
db:JVNDBid:JVNDB-2017-009486
db:CNNVDid:CNNVD-201710-499
db:NVDid:CVE-2017-15304

LAST UPDATE DATE

2025-04-20T23:30:51.082000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-35541date:2017-11-30T00:00:00
db:VULHUBid:VHN-106113date:2017-11-07T00:00:00
db:JVNDBid:JVNDB-2017-009486date:2017-11-14T00:00:00
db:CNNVDid:CNNVD-201710-499date:2017-10-18T00:00:00
db:NVDid:CVE-2017-15304date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-35541date:2017-11-30T00:00:00
db:VULHUBid:VHN-106113date:2017-10-15T00:00:00
db:JVNDBid:JVNDB-2017-009486date:2017-11-14T00:00:00
db:CNNVDid:CNNVD-201710-499date:2017-10-18T00:00:00
db:NVDid:CVE-2017-15304date:2017-10-15T03:29:00.203