Siemens RUGGEDCOM NMS < V1.2 Cross-Site Request Forgery (CSRF) Vulnerability

Siemens RUGGEDCOM NMS < V1.2 Cross-Site Request Forgery (CSRF) Vulnerability

CVE-2017-2682 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

Learn more about our Web App Pen Testing.