HIGH · 9.3

CVE-2007-3786

Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the v...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
EsoftInstagate Ex2 Utmfirmware_3.1.20031001

References

FAQ

What is CVE-2007-3786?

CVE-2007-3786 is a vulnerability with a CVSS score of 9.3 (HIGH). Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the v...

How severe is CVE-2007-3786?

CVE-2007-3786 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3786?

Check the references section above for vendor advisories and patch information. Affected products include: Esoft Instagate Ex2 Utm.