HIGH · 8.8

CVE-2017-14011

A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site reque...

Vulnerability Description

A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker to execute unauthorized code, resulting in changes to the configuration of the device.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ProminentMultiflex M10A Controller FirmwareAll versions
ProminentMultiflex M10A Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-14011?

CVE-2017-14011 is a vulnerability with a CVSS score of 8.8 (HIGH). A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site reque...

How severe is CVE-2017-14011?

CVE-2017-14011 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-14011?

Check the references section above for vendor advisories and patch information. Affected products include: Prominent Multiflex M10A Controller Firmware, Prominent Multiflex M10A Controller.