The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: siemens

Published: 2017-03-29T01:00:00

Updated: 2017-07-11T09:57:01

Reserved: 2016-12-01T00:00:00


Link: CVE-2017-2688

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-03-29T01:59:01.783

Modified: 2017-07-12T01:29:15.067


Link: CVE-2017-2688

JSON object: View

cve-icon Redhat Information

No data.

CWE