Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2746

Опубликовано: 11 июл. 2023
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

The Rockwell Automation Enhanced HIM software contains

an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit this vulnerability, a malicious user would have to convince a user to click on an untrusted link through a social engineering attack or successfully perform a Cross Site Scripting Attack (XSS). Exploitation of a CSRF could potentially lead to sensitive information disclosure and full remote access to the affected products.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:enhanced_him:1.001:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00138
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 9.6
github
больше 2 лет назад

The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit this vulnerability, a malicious user would have to convince a user to click on an untrusted link through a social engineering attack or successfully perform a Cross Site Scripting Attack (XSS). Exploitation of a CSRF could potentially lead to sensitive information disclosure and full remote access to the affected products.

CVSS3: 9.6
fstec
больше 2 лет назад

Уязвимость реализации прикладного программного интерфейса программного обеспечения управления процессами и мониторинга систем автоматизации Rockwell Automation Enhanced HIM, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 34%
0.00138
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-352
CWE-352