CVE-2007-3786
Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.55% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- esoft/instagate ex2 utm
- Source
- cve@mitre.org
References
- http://labs.calyptix.com/CX-2007-05.phpPatch, Vendor Advisory
- http://labs.calyptix.com/CX-2007-05.txtPatch, Vendor Advisory
- http://osvdb.org/38174
- http://secunia.com/advisories/26005
- http://www.eweek.com/article2/0%2C1759%2C2154646%2C00.asp
- http://www.securityfocus.com/archive/1/473663/100/0/threaded
- http://www.vupen.com/english/advisories/2007/2539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35372
- http://labs.calyptix.com/CX-2007-05.phpPatch, Vendor Advisory
- http://labs.calyptix.com/CX-2007-05.txtPatch, Vendor Advisory
- http://osvdb.org/38174
- http://secunia.com/advisories/26005
- http://www.eweek.com/article2/0%2C1759%2C2154646%2C00.asp
- http://www.securityfocus.com/archive/1/473663/100/0/threaded
- http://www.vupen.com/english/advisories/2007/2539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35372
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.