Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.

Published: 2023-12-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * ioLogik E1200 Series : Please contact Moxa Technical Support for the security patch (v3.3.7). https://www.moxa.com/tw/support/technical-support

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58232 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
History

Wed, 27 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Moxa Iologik E1210 Iologik E1210 Firmware Iologik E1211 Iologik E1211 Firmware Iologik E1212 Iologik E1212 Firmware Iologik E1213 Iologik E1213 Firmware Iologik E1214 Iologik E1214 Firmware Iologik E1240 Iologik E1240 Firmware Iologik E1241 Iologik E1241 Firmware Iologik E1242 Iologik E1242 Firmware Iologik E1260 Iologik E1260 Firmware Iologik E1262 Iologik E1262 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2024-11-27T18:28:44.244Z

Reserved: 2023-11-06T07:47:31.237Z

Link: CVE-2023-5961

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.125Z

cve-icon NVD

Status : Modified

Published: 2023-12-23T09:15:07.730

Modified: 2024-11-21T08:42:52.213

Link: CVE-2023-5961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses