PT-2009-4262 · American Power Conversion · Network Management Card+1

Russ Mcree

·

Published

2009-12-28

·

Updated

2010-06-29

·

CVE-2009-1797

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: American Power Conversion (APC) Switched Rack PDU devices (affected versions not specified)
Description: The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) of affected devices. These vulnerabilities allow remote attackers to hijack the authentication of administrator or device users for requests, potentially creating new administrative users or having other unspecified impacts.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1797

Affected Products

Apc Switched Rack Pdu
Network Management Card