A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A | Mitigation Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-06-29 20:29
Updated : 2019-10-09 16:28
NVD link : CVE-2017-6038
Mitre link : CVE-2017-6038
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
belden_hirschmann
- gecko_lite_managed_switch
- gecko_lite_managed_switch_firmware