CVE-2023-5961
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- moxa/iologik e1210 firmware · moxa/iologik e1211 firmware · moxa/iologik e1212 firmware · moxa/iologik e1213 firmware · moxa/iologik e1214 firmware · moxa/iologik e1240 firmware · moxa/iologik e1241 firmware · moxa/iologik e1242 firmware · moxa/iologik e1260 firmware · moxa/iologik e1262 firmware
- Source
- psirt@moxa.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.