8.8

CVE-2021-31584

Exploit
Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SipwiseNext Generation Communication Platform Version3.6.4 SwEditionce
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

http://lists.sipwise.com/pipermail/spce-user_lists.sipwise.com/2021-September/014708.html
Vendor Advisory
Mailing List
https://www.sipwise.com
Product
https://www.zeroscience.mk/en/vulnerabilities
Third Party Advisory
Exploit
http://packetstormsecurity.com/files/162318/Sipwise-C5-NGCP-CSC-Cross-Site-Request-Forgery.html
Third Party Advisory
Exploit
VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5649.php
Third Party Advisory