There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HRiello Ups Netman 204
HWRiello-Upswszystkie wersjeRiello Ups Netman 204 Firmware
OSRiello-Ups02.05
Powiązane podatności
Podatność mechanizmu odzyskiwania hasła w Riello Netman 204 umożliwia przejęcie urządzenia
RCE w Riello-Ups NetMan 204 — upload webshella przez firmware
Riello NetMan 204 — command injection i bypass uwierzytelnienia
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the a...
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It ...