CVE-2023-5961

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*

History

28 Dec 2023, 15:26

Type Values Removed Values Added
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-352
CPE cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*

23 Dec 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-23 09:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-5961

Mitre link : CVE-2023-5961

CVE.ORG link : CVE-2023-5961


JSON object : View

Products Affected

moxa

  • iologik_e1241
  • iologik_e1242_firmware
  • iologik_e1213
  • iologik_e1212_firmware
  • iologik_e1213_firmware
  • iologik_e1260
  • iologik_e1260_firmware
  • iologik_e1214
  • iologik_e1211
  • iologik_e1240_firmware
  • iologik_e1262_firmware
  • iologik_e1242
  • iologik_e1240
  • iologik_e1211_firmware
  • iologik_e1214_firmware
  • iologik_e1262
  • iologik_e1210_firmware
  • iologik_e1212
  • iologik_e1241_firmware
  • iologik_e1210
CWE
CWE-352

Cross-Site Request Forgery (CSRF)