A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A | Mitigation Third Party Advisory US Government Resource |
https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A | Mitigation Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A - Mitigation, Third Party Advisory, US Government Resource |
Information
Published : 2017-06-30 03:29
Updated : 2024-11-21 03:28
NVD link : CVE-2017-6038
Mitre link : CVE-2017-6038
CVE.ORG link : CVE-2017-6038
JSON object : View
Products Affected
belden_hirschmann
- gecko_lite_managed_switch_firmware
- gecko_lite_managed_switch
CWE
CWE-352
Cross-Site Request Forgery (CSRF)