An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.cassianetworks.com/products/iot-access-controller/ | product |
https://github.com/Dodge-MPTC/CVE-2023-35793-CSRF-On-Web-SSH | third party advisory exploit |
https://blog.kscsc.online/cves/202335793/md.html |