CRITICAL · 10.0

CVE-2017-5145

An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulne...

Vulnerability Description

An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.

CVSS Score

10.0

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CarlosgavazziVmu-C Em Firmware-
CarlosgavazziVmu-C Em-
CarlosgavazziVmu-C Pv Firmware-
CarlosgavazziVmu-C Pv-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-5145?

CVE-2017-5145 is a vulnerability with a CVSS score of 10.0 (CRITICAL). An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulne...

How severe is CVE-2017-5145?

CVE-2017-5145 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-5145?

Check the references section above for vendor advisories and patch information. Affected products include: Carlosgavazzi Vmu-C Em Firmware, Carlosgavazzi Vmu-C Em, Carlosgavazzi Vmu-C Pv Firmware, Carlosgavazzi Vmu-C Pv.