Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-327p-j9g4-qf3q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость интерфейса мониторинга и управления операционной системы Cisco FXOS межсетевого экрана Cisco Firepower, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-352