PT-2021-15564 · Bosch · Cpp Firmware+7
Andrey Muravitsky
·
Published
2021-08-05
·
Updated
2021-08-12
·
CVE-2021-23849
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
No specific software or versions mentioned.
Description:
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user. This is a Cross Site Request Forgery (CSRF) issue, which requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpp Firmware
Aviotec Firmware
Cpp13 Firmware
Cpp14 Firmware
Cpp4 Firmware
Cpp6 Firmware
Cpp7.3 Firmware
Cpp7 Firmware