PT-2024-21879 · Planet · Planet Igs-4215-16T2S
Dan1T0
+1
·
Published
2024-03-21
·
Updated
2024-04-11
·
CVE-2024-2741
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Planet IGS-4215-16T2S version 1.305b210528
Description
The issue is a Cross-Site Request Forgery (CSRF) vulnerability that could allow a remote attacker to trick some authenticated users into performing actions in their session. This includes actions such as adding or updating accounts through the Switch web interface.
Recommendations
For Planet IGS-4215-16T2S version 1.305b210528, consider disabling access to the web interface until a patch is available to prevent exploitation of the CSRF vulnerability. Restrict access to the Switch web interface to minimize the risk of unauthorized account modifications.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Planet Igs-4215-16T2S