Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6634

Опубликовано: 22 мая 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the Device Manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the Device Manager web interface and with the privileges of the user. Cisco Bug IDs: CSCvc88811.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:industrial_ethernet_1000_series_firmware:1.3_base:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:cisco:ie-1000-4p2s-lm:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ie-1000-4t1t-lm:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ie-1000-6t2t-lm:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ie-1000-8p2s-lm:-:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00217
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the Device Manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the Device Manager web interface and with the privileges of the user. Cisco Bug IDs: CSCvc88811.

EPSS

Процентиль: 44%
0.00217
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352