Vulnerability Description
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change arbitrary device settings by tricking a legitimate device administrator to click on a malicious link.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | 7Kt Pac1260 Data Manager Firmware | All versions |
| Siemens | 7Kt Pac1260 Data Manager | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-41795?
CVE-2024-41795 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could all...
How severe is CVE-2024-41795?
CVE-2024-41795 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41795?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens 7Kt Pac1260 Data Manager Firmware, Siemens 7Kt Pac1260 Data Manager.