CVE-2024-45372: CSRF
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45372?
CVE-2024-45372 is classified as a critical vulnerability due to its potential to allow unauthorized changes to user settings.
How do I fix CVE-2024-45372?
To fix CVE-2024-45372, users should upgrade to firmware version 1.05 or later for the Planex MZK-DP300N.
What type of vulnerability is CVE-2024-45372?
CVE-2024-45372 is a cross-site request forgery (CSRF) vulnerability.
What can happen if I am affected by CVE-2024-45372?
If affected by CVE-2024-45372, a user may inadvertently change their login password or perform other unintended operations.
Which devices are impacted by CVE-2024-45372?
CVE-2024-45372 impacts the Planex MZK-DP300N firmware versions 1.04 and earlier.