Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Siemens SINEC Traffic Analyzer 跨站请求伪造漏洞
Vulnerability Description
Siemens SINEC Traffic Analyzer是德国西门子(Siemens)公司的一款网络流量分析工具。 Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) V1.2 版本存在跨站请求伪造漏洞,该漏洞源于受影响设备的 Web 界面容易受到跨站请求伪造攻击,通过诱骗经过身份验证的用户点击恶意链接,攻击者可以代表受害用户在设备上执行任意操作。
CVSS Information
N/A
Vulnerability Type
N/A