A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T14:55:34.857Z

Reserved: 2017-01-03T00:00:00

Link: CVE-2017-5156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-04-20T20:59:00.237

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-5156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.