First published: Sun Dec 29 2019(Updated: )
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netis-systems Dl4343 Firmware | ||
Netis-systems Dl4343 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Netis DL4323 vulnerability is CVE-2019-20071.
The severity of CVE-2019-20071 is medium with a CVSS score of 6.5.
The affected software for CVE-2019-20071 is Netis DL4343 Firmware.
The CSRF vulnerability in CVE-2019-20071 occurs via form2logaction.cgi to delete all logs on Netis DL4323 devices.
No, Netis DL4343 is not affected by CVE-2019-20071.
To fix the CSRF vulnerability in CVE-2019-20071, update Netis DL4323 firmware to the latest version.
You can find more information about the vulnerability CVE-2019-20071 in the references provided: [1](https://drive.google.com/open?id=1XtSsH-1ApxRS7VExubz8zBEyENVQGhUc), [2](https://drive.google.com/open?id=1p4HJ5C20TqY0rVNffdD5Zd7S_bGvDhnk), [3](https://fatihhcelik.blogspot.com/2019/12/csrf-vulnerability-on-clean-log-netis.html).