CVE-2014-5361: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5361?
CVE-2014-5361 is classified as a medium severity vulnerability due to its potential to allow attackers to hijack sessions.
How do I fix CVE-2014-5361?
To fix CVE-2014-5361, update Landesk Management Suite to a version later than 9.6 that addresses these vulnerabilities.
What types of attacks can CVE-2014-5361 facilitate?
CVE-2014-5361 can facilitate cross-site request forgery (CSRF) attacks, allowing unauthorized actions to be performed on behalf of an administrator.
Who is affected by CVE-2014-5361?
CVE-2014-5361 affects users of Landesk Management Suite versions 9.6 and earlier.
What actions can be hijacked due to CVE-2014-5361?
CVE-2014-5361 allows attackers to potentially hijack the authentication for starting, stopping, or restarting services.