CVE-2022-3372 HIGH

CVE-2022-3372: Cross-Site Request Forgery (CSRF) in Riello UPS Netman-204

Vendor Riello Ups
Product Netman-204
Weakness CWE-352 · CSRF
Published June 21, 2023
Last update December 6, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper validation on the CRSF token. This vulnerability could allow a remote attacker to access the administrator panel, being able to modify different parameters that are critical for industrial operations.

Key dates

02Disclosure timeline

June 21, 2023 CVE published
December 6, 2024 Record updated

Related vulnerabilities

04Related CVE