CVE-2021-34086
https://notcve.org/view.php?id=CVE-2021-34086
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify incoming requests. En la impresora 3D Ultimaker S3, la impresora 3D Ultimaker S5, la impresora 3D Ultimaker 3 S-line versiones hasta 6.3 y la Ultimaker 3 versiones hasta 5.2.16, el servidor web local aloja APIs vulnerables a ataques de tipo CSRF. No verifican las peticiones entrantes • https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf https://ultimaker.com/3d-printers/ultimaker-3 https://ultimaker.com/3d-printers/ultimaker-s3 https://ultimaker.com/3d-printers/ultimaker-s5 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-34087
https://notcve.org/view.php?id=CVE-2021-34087
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page. En la impresora 3D Ultimaker S3, la impresora 3D Ultimaker S5, la impresora 3D Ultimaker 3 S-line versiones hasta 6.3 y la Ultimaker 3 versiones hasta 5.2.16, el servidor web local puede ser usado para hacer clickjacking. Esto incluye la página de configuración • https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf https://ultimaker.com/3d-printers/ultimaker-s3 https://ultimaker.com/3d-printers/ultimaker-s5 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •