PT-2024-31585 · Planex · Planex Mzk-Dp300N

Kentaro Ishii

·

Published

2024-09-25

·

Updated

2024-10-03

·

CVE-2024-45372

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PLANEX MZK-DP300N firmware versions 1.04 and earlier
Description The issue is related to a cross-site request forgery vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations, such as changing the login password.
Recommendations For firmware versions 1.04 and earlier, update to a patched version as soon as possible and enforce strict CSRF token validation. As a temporary workaround, consider restricting access to the web management page until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-45372

Affected Products

Planex Mzk-Dp300N