CVE-2022-32516: CSRF
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32516?
CVE-2022-32516 is a Cross-Site Request Forgery (CSRF) vulnerability that can result in system configurations being overridden and causing a reboot loop on the affected product, Conext™ ComBox.
What is the severity of CVE-2022-32516?
The severity of CVE-2022-32516 is high with a CVSS severity score of 6.5.
Which products are affected by CVE-2022-32516?
The vulnerability affects all versions of Schneider-electric Conext ComBox firmware.
How does CVE-2022-32516 work?
CVE-2022-32516 exploits POST-Based Cross-Site Request Forgery (CSRF) to manipulate system configurations and trigger a reboot loop.
Is Schneider-electric Conext ComBox vulnerable to CVE-2022-32516?
No, Schneider-electric Conext ComBox itself is not vulnerable to CVE-2022-32516.
How can I fix CVE-2022-32516?
Apply the latest firmware update provided by Schneider Electric to mitigate the CSRF vulnerability (CVE-2022-32516).