Lucene search

K
nvd[email protected]NVD:CVE-2024-35207
HistoryJun 11, 2024 - 12:15 p.m.

CVE-2024-35207

2024-06-1112:15:16
CWE-352
web.nvd.nist.gov
7
sinec traffic analyzer
web interface
cross-site request forgery
csrf attacks
authenticated victim user
malicious link

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.6%

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.

Affected configurations

Nvd
Node
siemenssinec_traffic_analyzerRange<1.2
VendorProductVersionCPE
siemenssinec_traffic_analyzer*cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.6%

Related for NVD:CVE-2024-35207