CVE-2023-5961
Last modified
CVE-2023-5961 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Iologik E1210 Firmware | < 3.3 |
| Moxa | Iologik E1211 Firmware | < 3.3 |
| Moxa | Iologik E1212 Firmware | < 3.3 |
| Moxa | Iologik E1213 Firmware | < 3.3 |
| Moxa | Iologik E1214 Firmware | < 3.3 |
| Moxa | Iologik E1240 Firmware | < 3.3 |
| Moxa | Iologik E1241 Firmware | < 3.3 |
| Moxa | Iologik E1242 Firmware | < 3.3 |
| Moxa | Iologik E1260 Firmware | < 3.3 |
| Moxa | Iologik E1262 Firmware | < 3.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5961?
How severe is CVE-2023-5961?
How do I fix CVE-2023-5961?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5955The Contact Form Email WordPress plugin before 1.3.44 does n…4.8
- CVE-2023-5956The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sani…4.8
- CVE-2023-5957The Ni Purchase Order(PO) For WooCommerce WordPress plugin t…7.2
- CVE-2023-5958The POST SMTP Mailer WordPress plugin before 2.7.1 does not …6.1
- CVE-2023-5959A vulnerability, which was classified as problematic, was fo…4.3
- CVE-2023-5960An improper privilege management vulnerability in the hotspo…5.5
- CVE-2023-5962A weak cryptographic algorithm vulnerability has been identi…6.5
- CVE-2023-5963An issue has been discovered in GitLab EE with Advanced Sear…4.3
- CVE-2023-5964The 1E-Exchange-DisplayMessageinstruction that is part of th…7.2
- CVE-2023-5965An authenticated privileged attacker could upload a speciall…7.2
- CVE-2023-5966An authenticated privileged attacker could upload a speciall…7.2
- CVE-2023-5967Mattermost fails to properly validate requests to the Calls …4.3
Are you affected by CVE-2023-5961?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
