Record summary

CVE-2020-13259 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE-2020-13260.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBRAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)ExploitDB exploitby Jonatan SchorNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubUrielYochpaz/CVE-2020-13259Repository PoCby UrielYochpazStars: 3Not analyzed4 files

86.5 KiB

GitHub

PoC details

References

3