PT-2023-30513 · Relyum · Rely-Pcie+1
Published
2023-12-12
·
Updated
2024-10-08
·
CVE-2023-47578
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Relyum RELY-PCIe version 22.2.1
Relyum RELY-REC version 23.1.0
Description
The issue is related to Cross Site Request Forgery (CSRF) attacks, which can be launched against the devices due to the absence of CSRF protection in the web interface. This allows an attacker to trick a user into performing unintended actions on the web application.
Recommendations
For Relyum RELY-PCIe version 22.2.1, consider disabling access to the web interface until a patch is available.
For Relyum RELY-REC version 23.1.0, restrict access to the web interface to minimize the risk of exploitation.
As a temporary workaround, consider implementing additional security measures, such as validating user requests and verifying the origin of requests to prevent CSRF attacks.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rely-Pcie
Rely-Rec