Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9jx-f6w8-8hj9

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.

This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.

This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.

EPSS

Процентиль: 55%
0.00322
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость веб-интерфейса операционных систем Cisco IOS и IOS XE, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 55%
0.00322
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-352