Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m249-8gm7-xrcf

Опубликовано: 11 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.

EPSS

Процентиль: 55%
0.00328
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.

CVSS3: 7.8
fstec
больше 1 года назад

Уязвимость веб-интерфейса программного средства мониторинга и анализа сетевого трафика в промышленных сетях SINEC Traffic Analyzer, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 55%
0.00328
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-352