Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2395 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative web interface in the proxy server on Fox-IT Fox DataDiode appliances before 1.7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create administrative users, (2) remove administrative users, or (3) change permissions. |
Solution
Fox-IT has released Version 1.7.2 of the Fox DataDiode Appliance that resolves the reported vulnerability. A Fox-IT product advisory titled “Fox DataDiode Appliance 1.7.2 advisory,” containing background and preparation information, as well as the upgrade instructions, are available by contacting the local Fox-IT customer support. Fox-IT also recommends the following actions: * All users of the Fox DataDiode Appliance should upgrade their systems to Version 1.7.2. * This installation consists of a reinstallation of the new version of the software. Therefore, the existing software configuration should be exported before this upgrade. This configuration can then be restored after the upgrade. * Users are advised to change all passwords of administrator and user accounts in the Fox DataDiode Appliance, plus passwords used for FTP/SSL connections.
Workaround
No workaround given by the vendor.
Fri, 03 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Fox-IT DataDiode Appliance CSRF | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-10-03T17:19:27.344Z
Reserved: 2014-03-13T00:00:00
Link: CVE-2014-2358
No data.
Status : Deferred
Published: 2014-10-19T01:55:10.107
Modified: 2025-10-03T18:15:34.077
Link: CVE-2014-2358
No data.
OpenCVE Enrichment
No data.
EUVD