VulnerabilityModified
CVE-2018-16172
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
MEDIUM 6.5EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- cybozu/remote service manager
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN23161885/index.htmlThird Party Advisory
- https://kb.cybozu.support/article/35260/Vendor Advisory
- https://jvn.jp/en/jp/JVN23161885/index.htmlThird Party Advisory
- https://kb.cybozu.support/article/35260/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.