Back

MEDIUM

Fox-IT DataDiode Appliance CSRF

Published Oct 19, 2014

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative web interface in the proxy server on Fox-IT Fox DataDiode appliances before 1.7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create administrative users, (2) remove administrative users, or (3) change permissions.

Affected products

Remediation

Vendor solution

Fox-IT has released Version 1.7.2 of the Fox DataDiode Appliance that resolves the reported vulnerability. A Fox-IT product advisory titled “Fox DataDiode Appliance 1.7.2 advisory,” containing background and preparation information, as well as the upgrade instructions, are available by contacting the local Fox-IT customer support.

Fox-IT also recommends the following actions:

* All users of the Fox DataDiode Appliance should upgrade their systems to Version 1.7.2.

* This installation consists of a reinstallation of the new version of the software. Therefore, the existing software configuration should be exported before this upgrade. This configuration can then be restored after the upgrade.

* Users are advised to change all passwords of administrator and user accounts in the Fox DataDiode Appliance, plus passwords used for FTP/SSL connections.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 19, 2014
Updated Oct 3, 2025
Reserved Mar 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a