6.8
CVE-2009-0056
- EPSS 0.23%
- Veröffentlicht 16.01.2009 21:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ironport Encryption Appliance Version6.2.4
Cisco ≫ Ironport Encryption Appliance Version6.2.4.1
Cisco ≫ Ironport Encryption Appliance Version6.2.5
Cisco ≫ Ironport Encryption Appliance Version6.2.6
Cisco ≫ Ironport Encryption Appliance Version6.2.7
Cisco ≫ Ironport Encryption Appliance Version6.2.7.1
Cisco ≫ Ironport Encryption Appliance Version6.2.7.2
Cisco ≫ Ironport Encryption Appliance Version6.2.7.3
Cisco ≫ Ironport Encryption Appliance Version6.2.7.4
Cisco ≫ Ironport Encryption Appliance Version6.2.7.5
Cisco ≫ Ironport Encryption Appliance Version6.2.7.6
Cisco ≫ Ironport Encryption Appliance Version6.3
Cisco ≫ Ironport Encryption Appliance Version6.3.0.1
Cisco ≫ Ironport Encryption Appliance Version6.3.0.2
Cisco ≫ Ironport Encryption Appliance Version6.3.0.3
Cisco ≫ Ironport Encryption Appliance Version6.5
Cisco ≫ Ironport Encryption Appliance Version6.5.0.1
Cisco ≫ Ironport Postx Version6.2.1
Cisco ≫ Ironport Postx Version6.2.2
Cisco ≫ Ironport Postx Version6.2.2.1
Cisco ≫ Ironport Postx Version6.2.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.424 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.