vde-2024-023

MEDIUM CVSS 6.5 csaf_welotecgmbh
Description

Welotec has been informed by an external source that the WebUI of the device management solution "SMART EMS" and the remote connectivity solution "VPN Security Suite" is vulnerable to so-called "Clickjacking" and advises to update to version v3.1.4 or later.

Timeline
Published
2024-04-23 08:00 UTC
Last Modified
2024-04-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      }
    ],
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "Welotec has been informed by an external source that the WebUI of the device management solution \"SMART EMS\" and the remote connectivity solution \"VPN Security Suite\" is vulnerable to so-called \"Clickjacking\" and advises to update to version v3.1.4 or later.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Please see the CVE description.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "This vulnerability can be mitigated with the use of an additional Reverse Proxy and / or Web Application Firewall protecting the WebUI.",
        "title": "Mitigation"
      },
      {
        "category": "description",
        "text": "Update the software to version 3.1.4 or later and configure the Content Security Policy (CSP).",
        "title": "Remediation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@welotec.com",
      "name": "Welotec GmbH",
      "namespace": "https://welotec.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "VDE-2024-023: Welotec: Clickjacking Vulnerability in WebUI - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2024-023/"
      },
      {
        "category": "self",
        "summary": "VDE-2024-023: Welotec: Clickjacking Vulnerability in WebUI - CSAF",
        "url": "https://welotec.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-023.json"
      },
      {
        "category": "external",
        "summary": "Vendor PSIRT",
        "url": "https://welotec.com"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Welotec GmbH",
        "url": "https://certvde.com/en/advisories/vendor/welotec/"
      }
    ],
    "title": "Welotec: Clickjacking Vulnerability in WebUI",
    "tracking": {
      "aliases": [
        "VDE-2024-023"
      ],
      "current_release_date": "2024-04-23T08:00:00.000Z",
      "generator": {
        "date": "2025-04-14T09:32:10.211Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.23"
        }
      },
      "id": "VDE-2024-023",
      "initial_release_date": "2024-04-23T08:00:00.000Z",
      "revision_history": [
        {
          "date": "2024-04-23T08:00:00.000Z",
          "number": "1",
          "summary": "Initial revision."
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "<3.1.4",
                    "product": {
                      "name": "SMART EMS <3.1.4",
                      "product_id": "CSAFPID-51001"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.1.4",
                    "product": {
                      "name": "SMART EMS 3.1.4",
                      "product_id": "CSAFPID-52001"
                    }
                  }
                ],
                "category": "product_name",
                "name": "SMART EMS"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "<3.1.4",
                    "product": {
                      "name": "VPN Security Suite <3.1.4",
                      "product_id": "CSAFPID-51002"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.1.4",
                    "product": {
                      "name": "VPN Security Suite 3.1.4",
                      "product_id": "CSAFPID-52002"
                    }
                  }
                ],
                "category": "product_name",
                "name": "VPN Security Suite"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Welotec"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFPID-51001",
          "CSAFPID-51002"
        ],
        "summary": "Affected products."
      },
      {
        "group_id": "CSAFGID-0002",
        "product_ids": [
          "CSAFPID-52001",
          "CSAFPID-52002"
        ],
        "summary": "Fixed products."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-3911",
      "cwe": {
        "id": "CWE-1021",
        "name": "Improper Restriction of Rendered UI Layers or Frames"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames. \n",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-52001",
          "CSAFPID-52002"
        ],
        "known_affected": [
          "CSAFPID-51001",
          "CSAFPID-51002"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "This vulnerability can be mitigated with the use of an additional Reverse Proxy and / or Web Application Firewall protecting the WebUI.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update the software to version 3.1.4 or later and configure the Content Security Policy (CSP).",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51001",
            "CSAFPID-51002"
          ]
        }
      ],
      "title": "CVE-2024-3911"
    }
  ]
}
View JSON API Download JSON