PT-2023-13315 · Unknown · Netman 204

David Cámara Galindo

·

Published

2023-06-21

·

Updated

2023-06-28

·

CVE-2022-3372

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netman-204 version 02.05
Description The issue is related to a CSRF vulnerability that allows an attacker to change administrator passwords due to the lack of proper validation on the CSRF token. This could enable a remote attacker to access the administrator panel and modify critical parameters for industrial operations.
Recommendations For Netman-204 version 02.05, consider implementing proper validation on the CSRF token to prevent Cross Site Request Forgery attacks. As a temporary workaround, restrict access to the administrator panel to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3372

Affected Products

Netman 204