CVE-2021-29660
02.04.2021, 19:15
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.
Vendor | Product | Version |
---|---|---|
softing | opc_toolbox | 𝑥 ≤ 4.10.1.13035 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration