A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.
2020-06-16T20:15:15.130
2024-11-21T05:37:16.327
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | easergy_t300_firmware | ≤ 1.5.2 | Yes |
Hardware | schneider-electric | easergy_t300 | - | No |