CVE-2017-5156: CSRF
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5156?
CVE-2017-5156 has been classified as a medium severity vulnerability due to its potential to allow unauthorized access to internal systems.
How do I fix CVE-2017-5156?
To mitigate CVE-2017-5156, users should upgrade their Schneider Electric Wonderware InTouch Access Anywhere to a version later than 11.5.2.
What type of vulnerability is CVE-2017-5156?
CVE-2017-5156 is a Cross-Site Request Forgery (CSRF) vulnerability that allows external sites to forge client requests.
Who is affected by CVE-2017-5156?
CVE-2017-5156 affects users of Schneider Electric Wonderware InTouch Access Anywhere version 11.5.2 and earlier.
What can an attacker do with CVE-2017-5156?
An attacker exploiting CVE-2017-5156 can gain unauthorized access to internal RDP systems on behalf of an authenticated user.