ZeroHour

CVE-2017-20020

PoC
CVSS 3.1
8.8 high
EPSS
<1%p33
Published
()
Modified
Description

A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

Vendors
solar-log
Products
solar-log 250 firmware, solar-log 300 firmware, solar-log 500 firmware, solar-log 800e firmware, solar-log 1000 firmware, solar-log 1000 pm\+ firmware, solar-log 1200 firmware, solar-log 2000 firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.