PT-2007-5024 · Esoft · Esoft Instagate Ex2 Utm
Published
2007-07-15
·
Updated
2024-08-07
·
CVE-2007-3786
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eSoft InstaGate EX2 UTM device versions prior to 3.1.20070615
Description
A cross-site request forgery (CSRF) issue allows remote attackers to perform privileged actions as administrators. The vendor disputes the distribution of the vulnerable software, stating it was a custom build for a former customer.
Recommendations
For versions prior to 3.1.20070615, update the firmware to version 3.1.20070615 or later to resolve the issue. As a temporary workaround, consider restricting access to the device's administrative interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esoft Instagate Ex2 Utm