PT-2020-15624 · Fs.Com · Fs.Com S3900 24T4S

Ludovic Ortega

·

Published

2020-10-22

·

Updated

2020-11-02

·

CVE-2020-24033

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fs.com S3900 24T4S versions 1.7.0 and earlier
Description An issue was discovered that allows remote attackers to forge requests on behalf of a site administrator, enabling them to change all settings, including deleting users and creating new users with escalated privileges, due to the lack of an authentication or token authentication mechanism in the form.
Recommendations For fs.com S3900 24T4S versions 1.7.0 and earlier, consider implementing an authentication or token authentication mechanism in the form to prevent remote attackers from forging requests. As a temporary workaround, restrict access to the form and settings to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24033

Affected Products

Fs.Com S3900 24T4S