PT-2020-15624 · Fs.Com · Fs.Com S3900 24T4S
Ludovic Ortega
·
Published
2020-10-22
·
Updated
2020-11-02
·
CVE-2020-24033
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
fs.com S3900 24T4S versions 1.7.0 and earlier
Description
An issue was discovered that allows remote attackers to forge requests on behalf of a site administrator, enabling them to change all settings, including deleting users and creating new users with escalated privileges, due to the lack of an authentication or token authentication mechanism in the form.
Recommendations
For fs.com S3900 24T4S versions 1.7.0 and earlier, consider implementing an authentication or token authentication mechanism in the form to prevent remote attackers from forging requests. As a temporary workaround, restrict access to the form and settings to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fs.Com S3900 24T4S