CVE-2024-45372
CVSS V2 None
CVSS V3 None
Description
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.
Overview
- CVE ID
- CVE-2024-45372
- Assigner
- jpcert
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-26T04:06:47.174Z
- Last Modified Date
- 2024-09-26T04:06:47.174Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.planex.co.jp/support/download/mzk-dp300n/ | |
https://jvn.jp/en/jp/JVN81966868/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-45372 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45372 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 12:28:07 | Added to TrackCVE |