Vulnerabilities > CVE-2018-6909 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Rainmachine web Application
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |