First published: Mon Feb 27 2017(Updated: )
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Ruggedcom NMS | <=2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2682 is considered a high severity vulnerability due to the potential for remote attackers to execute administrative operations.
To mitigate CVE-2017-2682, update the Siemens Ruggedcom NMS software to version 1.2 or later.
CVE-2017-2682 is associated with Cross-Site Request Forgery (CSRF) attacks.
Users of Siemens Ruggedcom NMS versions prior to 1.2 are affected by CVE-2017-2682.
CVE-2017-2682 is a vulnerability that allows remote attackers to perform CSRF attacks on the Siemens Ruggedcom NMS web application.