// For flags

CVE-2023-5961

ioLogik E1200 Series: Cross-Site Request Forgery (CSRF) Vulnerability

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.

Se identificó una vulnerabilidad de Cross-Site Request Forgery (CSRF) en las versiones de firmware de la serie ioLogik E1200 v3.3 y anteriores. Un atacante puede aprovechar esta vulnerabilidad para engañar a un cliente para que realice una solicitud no intencionada al servidor web, que será tratada como una solicitud auténtica. Esta vulnerabilidad puede llevar a un atacante a realizar operaciones en nombre del usuario víctima.

*Credits: Reza Rashidi from HADESS
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-11-06 CVE Reserved
  • 2023-12-23 CVE Published
  • 2023-12-29 EPSS Updated
  • 2024-01-31 First Exploit
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
  • CAPEC-62: Cross Site Request Forgery
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Moxa
Search vendor "Moxa"
Iologik E1210 Firmware
Search vendor "Moxa" for product "Iologik E1210 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1210 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1210
Search vendor "Moxa" for product "Iologik E1210"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1211 Firmware
Search vendor "Moxa" for product "Iologik E1211 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1211 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1211
Search vendor "Moxa" for product "Iologik E1211"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1212 Firmware
Search vendor "Moxa" for product "Iologik E1212 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1212 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1212
Search vendor "Moxa" for product "Iologik E1212"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1213 Firmware
Search vendor "Moxa" for product "Iologik E1213 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1213 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1213
Search vendor "Moxa" for product "Iologik E1213"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1214 Firmware
Search vendor "Moxa" for product "Iologik E1214 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1214 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1214
Search vendor "Moxa" for product "Iologik E1214"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1240 Firmware
Search vendor "Moxa" for product "Iologik E1240 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1240 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1240
Search vendor "Moxa" for product "Iologik E1240"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1241 Firmware
Search vendor "Moxa" for product "Iologik E1241 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1241 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1241
Search vendor "Moxa" for product "Iologik E1241"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1242 Firmware
Search vendor "Moxa" for product "Iologik E1242 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1242 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1242
Search vendor "Moxa" for product "Iologik E1242"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1260 Firmware
Search vendor "Moxa" for product "Iologik E1260 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1260 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1260
Search vendor "Moxa" for product "Iologik E1260"
--
Safe
Moxa
Search vendor "Moxa"
Iologik E1262 Firmware
Search vendor "Moxa" for product "Iologik E1262 Firmware"
< 3.3
Search vendor "Moxa" for product "Iologik E1262 Firmware" and version " < 3.3"
-
Affected
in Moxa
Search vendor "Moxa"
Iologik E1262
Search vendor "Moxa" for product "Iologik E1262"
--
Safe