CVE-2012-0235: CSRF
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0235?
CVE-2012-0235 has been classified as a moderate severity vulnerability due to its ability to facilitate cross-site request forgery attacks.
How do I fix CVE-2012-0235?
To mitigate CVE-2012-0235, upgrade Advantech/BroadWin WebAccess to version 7.0 or later where the vulnerability is addressed.
What type of attack does CVE-2012-0235 allow?
CVE-2012-0235 allows remote attackers to perform cross-site request forgery attacks, which can hijack user authentication.
Which versions of Advantech WebAccess are affected by CVE-2012-0235?
CVE-2012-0235 affects Advantech WebAccess versions prior to 7.0, specifically versions 5.0 and inclusive of 6.0.
Who can be impacted by CVE-2012-0235?
Victims of CVE-2012-0235 can include any user of Advantech/BroadWin WebAccess who has not updated to a patched version.