PT-2009-4262 · American Power Conversion · Network Management Card+1
Russ Mcree
·
Published
2009-12-28
·
Updated
2010-06-29
·
CVE-2009-1797
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
American Power Conversion (APC) Switched Rack PDU devices (affected versions not specified)
Description:
The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) of affected devices. These vulnerabilities allow remote attackers to hijack the authentication of administrator or device users for requests, potentially creating new administrative users or having other unspecified impacts.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apc Switched Rack Pdu
Network Management Card