CSRF Token Disclosure in Broadcom Management Center Products
CVE-2019-18376

5.9MEDIUM

Key Information:

Vendor
Symantec
Vendor
CVE Published:
10 April 2020

Summary

A vulnerability in the Broadcom Management Center allows attackers to disclose CSRF tokens by accessing an authenticated user's web browser history or exploiting network devices that log or intercept traffic. This exposure facilitates CSRF attacks, potentially compromising the integrity of the Management Center and its operations.

Affected Version(s)

Symantec Management Center (MC) MC prior to 2.4.1.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.