Description
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-11024 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2019-010 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:39:09.989Z
Reserved: 2020-02-24T00:00:00.000Z
Link: CVE-2019-20480
No data.
Status : Modified
Published: 2020-02-24T15:15:11.503
Modified: 2024-11-21T04:38:35.013
Link: CVE-2019-20480
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD