HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-23825 HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:23:09.934Z

Reserved: 2021-03-24T00:00:00

Link: CVE-2020-36283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-24T16:15:15.277

Modified: 2024-11-21T05:29:12.303

Link: CVE-2020-36283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses