CVE-2016-4845: CSRF
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4845?
CVE-2016-4845 is classified as a critical vulnerability due to its potential for allowing unauthorized users to hijack authentication.
How do I fix CVE-2016-4845?
To fix CVE-2016-4845, users should update the firmware of the affected I-O DATA DEVICE models to version 2.04 or higher.
Which devices are affected by CVE-2016-4845?
CVE-2016-4845 affects multiple I-O DATA DEVICE models including HVL-A2.0, HVL-A3.0, and HVL-AT4.0 with firmware version 2.03.
What type of vulnerability is CVE-2016-4845?
CVE-2016-4845 is a cross-site request forgery (CSRF) vulnerability.
Can attackers exploit CVE-2016-4845 remotely?
Yes, attackers can exploit CVE-2016-4845 remotely to hijack the authentication of arbitrary users.