First published: Thu Oct 03 2024(Updated: )
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP IceWall Federation Agent |
See https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbmu04711en_us&docLocale=en_US
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42504 has been rated as a medium severity vulnerability.
To fix CVE-2024-42504, apply the latest security updates provided by HPE for IceWall Agent products.
CVE-2024-42504 enables attackers to perform Cross-Site Request Forgery (CSRF) attacks during the login process.
Yes, CVE-2024-42504 can be exploited remotely, allowing attackers to compromise the system without physical access.
CVE-2024-42504 affects HPE IceWall Agent products.