CVE-2024-11014: CSRF
Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11014?
CVE-2024-11014 is classified as a medium severity cross-site request forgery vulnerability.
How do I fix CVE-2024-11014?
To mitigate CVE-2024-11014, update your NEC UNIVERGE IX system to version 10.10.22 or higher.
What versions of NEC UNIVERGE IX are affected by CVE-2024-11014?
CVE-2024-11014 affects NEC UNIVERGE IX versions from 9.2 to 10.10.21, 10.8 up to 10.8.27, and 10.9 up to 10.9.14.
What type of vulnerability is CVE-2024-11014?
CVE-2024-11014 is a cross-site request forgery (CSRF) vulnerability.
What impact does CVE-2024-11014 have on affected systems?
CVE-2024-11014 allows an attacker to hijack the authentication of the management interface screens, compromising the system's security.