Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gm7-rp3m-mxhv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

EPSS

Процентиль: 12%
0.00039
Низкий

8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8
nvd
около 8 лет назад

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

EPSS

Процентиль: 12%
0.00039
Низкий

8 High

CVSS3

Дефекты

CWE-352