There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso-sci/cross-site-request-forgery-csrf-riello-ups-netman-204 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-06-21T12:47:01.693Z
Updated: 2023-06-21T12:47:01.693Z
Reserved: 2022-09-30T12:49:12.218Z
Link: CVE-2022-3372
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-21T13:15:09.673
Modified: 2023-06-28T17:45:46.973
Link: CVE-2022-3372
JSON object: View
Redhat Information
No data.
CWE