Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5809

Опубликовано: 13 фев. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:h:schneider-electric:ion5000:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7300:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7500:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7600:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8650:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8800:-:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00321
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

EPSS

Процентиль: 55%
0.00321
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352