PT-2024-31585 · Planex · Planex Mzk-Dp300N

·

CVE-2024-45372

·

Published

2024-09-25

·

Updated

2024-10-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PLANEX MZK-DP300N firmware versions 1.04 and earlier
Description The issue is related to a cross-site request forgery vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations, such as changing the login password.
Recommendations For firmware versions 1.04 and earlier, update to a patched version as soon as possible and enforce strict CSRF token validation. As a temporary workaround, consider restricting access to the web management page until a patch is available.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45372

Affected Products

Planex Mzk-Dp300N