CVE-2010-2594
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and earlier on Windows, Snare Agent 1.5.0 and earlier on Linux and AIX, Snare…
Does this matter?
Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and earlier on Windows, Snare Agent 1.5.0 and earlier on Linux and AIX, Snare Agent 1.4 and earlier on IRIX, Snare Epilog 1.5.3 and earlier on Windows, and Snare Epilog 1.2 and earlier on UNIX allow remote attackers to hijack the authentication of administrators for requests that (1) change the password or (2) change the listening port.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- intersect alliance/snare agent · intersect alliance/snare epilog
- Source
- cve@mitre.org
References
- http://holisticinfosec.org/content/view/144/45/Third Party Advisory
- http://secunia.com/advisories/39562Broken Link
- http://www.kb.cert.org/vuls/id/173009Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/41226Third Party Advisory, VDB Entry
- http://holisticinfosec.org/content/view/144/45/Third Party Advisory
- http://secunia.com/advisories/39562Broken Link
- http://www.kb.cert.org/vuls/id/173009Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/41226Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.