Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-7043

Опубликовано: 10 дек. 2013
Источник: nvd
CVSS2: 8.3
EPSS Низкий

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device via the Restart parameter to goform/restart; (3) modify Wi-Fi settings, as demonstrated by the WpaPreSharedKey parameter to goform/wlanSecurity; or (4) modify parental controls via the ParentalPassword parameter to goform/RgParentalBasic.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:scientific_atlanta__dpr\/epr2320_firmware:2.0.2:r1262-090417:*:*:*:*:*:*
cpe:2.3:h:cisco:scientific_atlanta__dpr\/epr2320:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:cisco:scientific_atlanta__dpr2325_firmware:2.0.2:r1262-090417:*:*:*:*:*:*
cpe:2.3:h:cisco:scientific_atlanta__dpr2325:-:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00797
Низкий

8.3 High

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device via the Restart parameter to goform/restart; (3) modify Wi-Fi settings, as demonstrated by the WpaPreSharedKey parameter to goform/wlanSecurity; or (4) modify parental controls via the ParentalPassword parameter to goform/RgParentalBasic.

EPSS

Процентиль: 74%
0.00797
Низкий

8.3 High

CVSS2

Дефекты

CWE-352