PT-2009-4262 · American Power Conversion · Network Management Card+1

Russ Mcree

·

Publicado

2009-12-28

·

Atualizado

2010-06-29

·

CVE-2009-1797

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: American Power Conversion (APC) Switched Rack PDU devices (affected versions not specified)
Description: The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) of affected devices. These vulnerabilities allow remote attackers to hijack the authentication of administrator or device users for requests, potentially creating new administrative users or having other unspecified impacts.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1797

Produtos afetados

Apc Switched Rack Pdu
Network Management Card