CVE Published: 27/02/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: siemens |
Vendor: n/a |
Product: RUGGEDCOM NMS All versions < V2.1 (Windows and Linux) Status : PUBLISHED
CVE-2017-2682 Description
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.