Back

HIGH

Cross-Site Request Forgery (CSRF) in Riello UPS Netman-204

Published Jun 21, 2023

Description

There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jun 21, 2023
Updated Dec 6, 2024
Reserved Sep 30, 2022
CISA Vulnrichment
Updated Dec 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Jun 21, 2023
Updated Dec 6, 2024
Exploited since n/a
EUVD-2022-42751