Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the Device Manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the Device Manager web interface and with the privileges of the user. Cisco Bug IDs: CSCvc88811.
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Cisco Industrial Ethernet 1000 Series Switches 跨站请求伪造漏洞
Vulnerability Description
Cisco Industrial Ethernet 1000 Series Switches是美国思科(Cisco)公司的工业级以太网1000系列交换机。 Cisco Industrial Ethernet 1000 Series Switches 1.3版本上的Device Manager Web界面存在跨站请求伪造漏洞,该漏洞源于程序没有充分的执行跨站请求伪造保护。远程攻击者可通过诱使界面的用户打开恶意的链接或访问攻击者控制的网站利用该漏洞实施未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A