CVE-2010-5191: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password, (2) modify a policy, or (3) restart the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5191?
CVE-2010-5191 is classified as a high severity vulnerability due to the potential for remote attackers to hijack administrator authentication.
How do I fix CVE-2010-5191?
To fix CVE-2010-5191, upgrade the Blue Coat ProxyAV appliance to version 3.2.6.1 or later.
What types of attacks can occur due to CVE-2010-5191?
CVE-2010-5191 allows attackers to perform actions such as changing passwords, modifying policies, or restarting the Blue Coat ProxyAV device.
Which Blue Coat products are affected by CVE-2010-5191?
CVE-2010-5191 affects the Blue Coat ProxyAV appliances running versions up to and including 3.2.6.
Can CVE-2010-5191 be exploited without user interaction?
Yes, CVE-2010-5191 can be exploited through cross-site request forgery, allowing attackers to hijack authentication without user interaction.