Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3148

Опубликовано: 04 мар. 2020
Источник: nvd
CVSS3: 7.1
CVSS3: 7.1
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit this vulnerability by persuading a targeted user, with an active administrative session on the affected device, to click a malicious link. A successful exploit could allow an attacker to change the device's configuration, which could include the ability to edit or create user accounts of any privilege level. Some changes to the device's configuration could negatively impact the availability of networking services for other devices on networks managed by CPNR.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:prime_network_registrar:*:*:*:*:*:*:*:*
Версия до 10.1 (исключая)

EPSS

Процентиль: 53%
0.00306
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit this vulnerability by persuading a targeted user, with an active administrative session on the affected device, to click a malicious link. A successful exploit could allow an attacker to change the device's configuration, which could include the ability to edit or create user accounts of any privilege level. Some changes to the device's configuration could negatively impact the availability of networking services for other devices on networks managed by CPNR.

CVSS3: 7.1
fstec
больше 5 лет назад

Уязвимость веб-интерфейса средства управления сетевыми сервисами Cisco Prime Network Registrar, позволяющая нарушителю осуществить межсайтовую подделку запросов

EPSS

Процентиль: 53%
0.00306
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352
CWE-352