CVE-2020-23593 Information

Description

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ’ /mgm_log_cfg.asp.’ The system starts to log events ‘Remote’ mode or ‘Both’ mode on \Syslog – Configuration page\ logs events and sends to remote syslog server IP and Port.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

https://github.com/huzaifahussain98/CVE-2020-23593

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: