Advisory ID | NN-2020:2-01 |
---|---|
Topic | Cross-site request forgery attack on change password form |
CWE Impact | CWE-352: Cross-Site Request Forgery (CSRF) |
Issue date | 2020-05-26 |
Affects | Guardian, CMC between v19.0.4 and v20.0.3 |
CVE Name(s) | NA |
CVSS Details | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS Score | 8.6 (CVSS v4.0) 8.8 (CVSS v3.1) |
CVE Risk Level | High (CVSS v4.0) High (CVSS v3.1) |
Risk Level for Nozomi customers | Medium |
Change password doesn't validate CSRF token properly.
An attacker can force the victim to change password without knowing. To successfully complete this attack the victim needs to be logged to the Guardian/CMC and visit a special prepared page containing the forged change password request. The change password request will be logged to the internal Guardian/CMC audit log and the victim session will be terminated. The attacked must have Guardian/CMC reachability to login into the system after a successful attack. Guardian/CMC starting from v19.0.4 are affected, versions before v19.0.4 are NOT affected.
Guardian, CMC between v19.0.4 and v20.0.3
Users should always pay attention to phishing emails and un-trusted links.
v19 series: Upgrade to v19.0.11 v20 series: Upgrade to v20.0.3
We thank the following parties for their efforts: