PT-2020-9559 · Adrem · Netcrunch

Published

2020-12-16

·

Updated

2020-12-17

·

CVE-2019-14481

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: AdRem NetCrunch version 10.6.0.4587
Description: The issue is a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page, which can lead to account takeover.
Recommendations: For AdRem NetCrunch version 10.6.0.4587, as a temporary workaround, consider restricting access to the NetCrunch web client until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14481

Affected Products

Netcrunch