CVE-2017-2682
27.02.2017, 11:59
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.
Vendor | Product | Version |
---|---|---|
siemens | ruggedcom_network_management_software | 𝑥 ≤ 2.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References