PT-2013-3913 · NetGear · Readynas Raidiator
Publicado
2013-12-12
·
Atualizado
2019-07-18
·
CVE-2013-2752
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NETGEAR ReadyNAS RAIDiator versions prior to 4.1.12
NETGEAR ReadyNAS RAIDiator versions 4.2.x prior to 4.2.24
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of users. This is due to a vulnerability in the frontview/lib/np handler.pl file.
Recommendations
For versions prior to 4.1.12, update to version 4.1.12 or later.
For versions 4.2.x prior to 4.2.24, update to version 4.2.24 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Readynas Raidiator