First published: Mon Dec 28 2009(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to hijack the authentication of (1) administrator or (2) device users for requests that create new administrative users or have unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
APC Network Management Card | ||
Apc Switched Rack Pdu Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1797 is considered to have a high severity due to the potential for exploitation through cross-site request forgery.
To fix CVE-2009-1797, it is recommended to apply the latest firmware updates from APC for affected devices.
CVE-2009-1797 affects APC's Network Management Card and Switched Rack PDU devices.
Yes, CVE-2009-1797 can allow remote attackers to hijack the authentication of administrators and users.
Yes, CVE-2009-1797 is directly related to web application security due to its cross-site request forgery vulnerabilities.