CVE-2020-24373

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
16/09/2020
Last modified:
16/11/2022

Description

A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:free:freebox_revolution_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_revolution:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_mini_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_one_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_one:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_delta_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_delta:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_pop_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_pop:-:*:*:*:*:*:*:*