CVE-2020-36283

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
24/03/2021
Last modified:
26/03/2021

Description

HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hidglobal:omnikey_5427_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:omnikey_5427:-:*:*:*:*:*:*:*
cpe:2.3:o:hidglobal:omnikey_5127_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:omnikey_5127:-:*:*:*:*:*:*:*