Cisco Industrial Ethernet 1000 Series Switches Device Manager Vulnerability
CVE-2017-6634

8.8HIGH

What is CVE-2017-6634?

A vulnerability exists in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3, which allows an unauthenticated remote attacker to execute cross-site request forgery (CSRF) attacks. The flaw is due to inadequate CSRF protection, enabling attackers to trick users into following malicious links or visiting compromised sites. By exploiting this vulnerability, attackers may send unauthorized requests to the affected device through the Device Manager interface, executing actions under the user's credentials. This poses significant security risks, as it can lead to unauthorized changes or actions on the devices managed by affected users.

Affected Version(s)

Cisco Industrial Ethernet 1000 Series Switches Cisco Industrial Ethernet 1000 Series Switches

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.