CVE-2017-6038 Information
Feb 14, 2021
cve
Description
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Reference
https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
LOW
Base Severity
7.1
Share on: