Exploitation Summary
EIP tracks 2 public exploits for CVE-2020-13259. PoCs published by Jonatan Schor, UrielYochpaz.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in RAD SecFlow-1v's web interface, allowing unauthenticated attackers to perform actions like device reboot by tricking authenticated users into visiting a malicious link. It can be combined with CVE-2020-13260 for full account takeover.
Description
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE-2020-13260.
Exploits (2)
This exploit demonstrates a CSRF vulnerability in RAD SecFlow-1v's web interface, allowing unauthenticated attackers to perform actions like device reboot by tricking authenticated users into visiting a malicious link. It can be combined with CVE-2020-13260 for full account takeover.
This PoC demonstrates a CSRF vulnerability in RAD SecFlow-1v's web interface, allowing unauthenticated attackers to perform actions with the privilege level of an authenticated user. The AttackerServer.py script captures the victim's cookie, which can be used for session hijacking.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H