CVE-2016-10313 Information

Description

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3) Air:Link 5000AC (AL5000AC) version 1.13 and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct CSRF attacks via certain /goform/* pages.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Reference

https://www.riskbasedsecurity.com/research/RBS-2016-004.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: