CVE-2021-31584
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
23/04/2021
Last modified:
30/07/2022
Description
Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sipwise:next_generation_communication_platform:3.6.4:*:*:*:ce:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.sipwise.com/pipermail/spce-user_lists.sipwise.com/2021-September/014708.html
- http://packetstormsecurity.com/files/162318/Sipwise-C5-NGCP-CSC-Cross-Site-Request-Forgery.html
- https://www.sipwise.com
- https://www.zeroscience.mk/en/vulnerabilities
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5649.php



