PT-2021-19432 · Sipwise · Sipwise C5 Ngcp Www Csc+1
Gjoko Krstic
·
Published
2021-04-23
·
Updated
2022-07-30
·
CVE-2021-31584
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sipwise C5 NGCP www csc version 3.6.4 up to and including platform NGCP CE mr3.8.13
Sipwise C5 NGCP www admin version 3.6.7
Description
The issue allows call/click2dial CSRF attacks for actions with administrative privileges. This can potentially lead to unauthorized actions being performed with administrative privileges.
Recommendations
For Sipwise C5 NGCP www csc version 3.6.4 up to and including platform NGCP CE mr3.8.13, consider implementing CSRF protection measures to prevent unauthorized actions.
For Sipwise C5 NGCP www admin version 3.6.7, restrict access to administrative actions to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sipwise C5 Ngcp Www Admin
Sipwise C5 Ngcp Www Csc