A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A | Mitigation Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2017-06-30 03:29
Updated : 2019-10-09 23:28
NVD link : CVE-2017-6038
Mitre link : CVE-2017-6038
CVE.ORG link : CVE-2017-6038
JSON object : View
Products Affected
belden_hirschmann
- gecko_lite_managed_switch_firmware
- gecko_lite_managed_switch
CWE
CWE-352
Cross-Site Request Forgery (CSRF)