1 results (0.004 seconds)
CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0
CVE-2022-3372 – Cross-Site Request Forgery (CSRF) in Riello UPS Netman-204
https://notcve.org/view.php?id=CVE-2022-3372
There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations. • https://www.incibe.es/en/incibe-cert/notices/aviso-sci/cross-site-request-forgery-csrf-riello-ups-netman-204 • CWE-352: Cross-Site Request Forgery (CSRF) •