First published: Tue Sep 14 2010(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct denial of service attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Proventia Network Mail Security System Virtual Appliance | ||
Ibm Proventia Network Mail Security System Virtual Appliance Firmware | =1.6 | |
Ibm Proventia Network Mail Security System Virtual Appliance Firmware | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0153 is classified as medium due to the potential for remote attackers to hijack administrator sessions.
To fix CVE-2010-0153, update the firmware of the IBM Proventia Network Mail Security System appliance to version 2.5.0.2 or later.
CVE-2010-0153 affects the IBM Proventia Network Mail Security System Virtual Appliance running firmware prior to version 2.5.0.2.
Yes, CVE-2010-0153 can be exploited remotely by attackers to perform cross-site request forgery actions.
CVE-2010-0153 enables attackers to hijack authentication and send unauthorized requests, which could result in malicious configuration changes.