Back

HIGH

PiiGAB M-Bus Cross-Site Request Forgery

Published Jul 6, 2023

Description

PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner of the device and hope that the owner clicks on the link. If the owner of the device has a cookie stored that allows the owner to be logged in, then the device could execute the GET or POST link request.

Affected products

Remediation

Vendor solution

PiiGAB created updated software to address these issues and encourages users to install the new update on their own gateway. The new software packages can be downloaded directly from the web UI in the gateway and older gateways can download it from Piigab.se http://www.piigab.se/  or Piigab.com https://www.piigab.com/ .

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Jul 6, 2023
Updated Nov 13, 2024
Reserved Jun 27, 2023

CISA Vulnrichment

Updated Nov 13, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Jul 6, 2023
Updated Nov 13, 2024

GitHub

No data