Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Iologik E1210 Firmware | < 3.3 |
| Moxa | Iologik E1210 | - |
| Moxa | Iologik E1211 Firmware | < 3.3 |
| Moxa | Iologik E1211 | - |
| Moxa | Iologik E1212 Firmware | < 3.3 |
| Moxa | Iologik E1212 | - |
| Moxa | Iologik E1213 Firmware | < 3.3 |
| Moxa | Iologik E1213 | - |
| Moxa | Iologik E1214 Firmware | < 3.3 |
| Moxa | Iologik E1214 | - |
| Moxa | Iologik E1240 Firmware | < 3.3 |
| Moxa | Iologik E1240 | - |
| Moxa | Iologik E1241 Firmware | < 3.3 |
| Moxa | Iologik E1241 | - |
| Moxa | Iologik E1242 Firmware | < 3.3 |
| Moxa | Iologik E1242 | - |
| Moxa | Iologik E1260 Firmware | < 3.3 |
| Moxa | Iologik E1260 | - |
| Moxa | Iologik E1262 Firmware | < 3.3 |
| Moxa | Iologik E1262 | - |
Related Weaknesses (CWE)
References
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-ioVendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-ioVendor Advisory
FAQ
What is CVE-2023-5961?
CVE-2023-5961 is a vulnerability with a CVSS score of 8.8 (HIGH). A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making...
How severe is CVE-2023-5961?
CVE-2023-5961 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5961?
Check the references section above for vendor advisories and patch information. Affected products include: Moxa Iologik E1210 Firmware, Moxa Iologik E1210, Moxa Iologik E1211 Firmware, Moxa Iologik E1211, Moxa Iologik E1212 Firmware.