Cross-Site Request Forgery Vulnerability in Moxa OnCell Products
CVE-2017-7917
8.8HIGH
Summary
A vulnerability exists in Moxa's OnCell series of products that allows attackers to exploit Cross-Site Request Forgery (CSRF) by sending unauthorized requests. The issue arises from the device's failure to properly verify whether a request was made by the actual user. This lack of verification could enable an attacker to modify the device's configuration settings without the user's consent, potentially leading to unauthorized access and further exploitation in industrial environments.
Affected Version(s)
Moxa OnCell Moxa OnCell
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved