VulnerabilityModified
CVE-2011-4498
Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrators for requests that wipe mobile devices.
MEDIUM 6.8EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrators for requests that wipe mobile devices.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- zenprise/zenprise device manager
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/584363Patch, US Government Resource
- http://www.zenpriseportal.com/patches/ZP_SecPatch_618_9995.zipPatch
- http://www.kb.cert.org/vuls/id/584363Patch, US Government Resource
- http://www.zenpriseportal.com/patches/ZP_SecPatch_618_9995.zipPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.