CVE-2022-3372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/06/2023
Last modified:
28/06/2023

Description

There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:riello-ups:netman_204_firmware:02.05:*:*:*:*:*:*:*
cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*