Cross-Site Request Forgery (CSRF) in Riello UPS Netman-204
CVE-2022-3372
8.8HIGH
What is CVE-2022-3372?
The Netman-204 by Riello UPS is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that could enable attackers to manipulate critical settings. Due to insufficient validation of the CSRF token, an attacker could execute unauthorized actions, such as changing administrator passwords. This exploitation could provide remote access to the administrator panel, allowing the modification of essential parameters that may compromise industrial operations.
Affected Version(s)
Netman-204 02.05
