A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-35238 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-02T03:07:46.833Z

Reserved: 2024-05-13T17:54:10.655Z

Link: CVE-2024-35207

cve-icon Vulnrichment

Updated: 2024-06-11T16:55:41.320Z

cve-icon NVD

Status : Modified

Published: 2024-06-11T12:15:16.600

Modified: 2024-11-21T09:19:56.387

Link: CVE-2024-35207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.