Lucene search

K
nvd[email protected]NVD:CVE-2023-39286
HistorySep 14, 2023 - 7:16 p.m.

CVE-2023-39286

2023-09-1419:16:50
CWE-352
web.nvd.nist.gov
1
cve-2023-39286
connect mobility router
cross site request forgery
insufficient request validation
system configuration settings

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.6%

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

Affected configurations

Nvd
Node
mitelconnect_mobility_routerRange<9.6.2307.111
VendorProductVersionCPE
mitelconnect_mobility_router*cpe:2.3:a:mitel:connect_mobility_router:*:*:*:*:*:*:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.6%

Related for NVD:CVE-2023-39286