CVE-2023-38579: Westermo Lynx 206-F2G Cross-Site Request Forgery
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38579?
CVE-2023-38579 is classified as a moderate severity vulnerability that could allow cross-site request forgery (CSRF) attacks.
How do I fix CVE-2023-38579?
To fix CVE-2023-38579, update the Westermo L206-f2g firmware to the latest version that addresses this vulnerability.
What software is affected by CVE-2023-38579?
CVE-2023-38579 affects the Westermo L206-f2g firmware version 4.24.
What type of attack can CVE-2023-38579 facilitate?
CVE-2023-38579 can facilitate cross-site request forgery (CSRF) attacks, allowing attackers to execute unauthorized actions on behalf of a victim.
Is the CSRF token in CVE-2023-38579 secure?
The CSRF token in CVE-2023-38579 may be predictable or easily guessable, which compromises its security.