CVE-2024-40883 Vulnerability Details

  /     /     /  

CVE-2024-40883 Metadata Quick Info

CVE Published: 01/08/2024 | CVE Updated: 26/11/2024 | CVE Year: 2024
Source: jpcert | Vendor: ELECOM CO.,LTD. | Product: WRC-X6000XS-G
Status : PUBLISHED

CVE-2024-40883 Description

Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-352
CWE Name: Cross-site request forgery (CSRF)
Source: ELECOM CO.,LTD.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).