CVE-2017-2682
CVE-2017-2682
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 1.4%KEV nãoPoC —Patch —
Ciclo de vida
27 feb 2017Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.
Productos afectados
n/a · RUGGEDCOM NMS All versions < V2.1 (Windows and Linux)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →