An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCarlosgavazzi Vmu C Em
HWCarlosgavazziall versionsCarlosgavazzi Vmu C Em Firmware
OSCarlosgavazziall versionsCarlosgavazzi Vmu C Pv
HWCarlosgavazziall versionsCarlosgavazzi Vmu C Pv Firmware
OSCarlosgavazziall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2017-5144CRITICAL9.8PL ✓same product
Brak uwierzytelnienia w urządzeniach Carlo Gavazzi VMU-C EM i PV
CVE-2017-5146HIGH7.5same product
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to fir...
CVE-2012-6427HIGH7.8same vendor
The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the...
CVE-2012-6428HIGH10.0same vendor
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-code...