Cross-Site Request Forgery Vulnerability in Dynacolor FCM-MB40 Devices
CVE-2019-13401
8.8HIGH
Summary
Dynacolor FCM-MB40 devices, particularly version 1.2.0.0, are susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities. This flaw exists in all scripts located under the cgi-bin directory, which could allow attackers to execute unauthorized commands on behalf of users. Proper measures should be taken to secure these devices and mitigate the risks associated with potential CSRF attacks.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved