8.8

CVE-2016-4845

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.

Data is provided by the National Vulnerability Database (NVD)
IodataHvl-a2.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-a3.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-a4.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at1.0s Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at2.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at2.0a Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at3.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at3.0a Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at4.0 Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
IodataHvl-at4.0a Firmware Version2.03
   IodataHvl-a Version-
   IodataHvl-at Version-
   IodataHvl-ata Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.58% 0.893
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.