CVE-2023-5961

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*

History

28 Dec 2023, 15:26

Type Values Removed Values Added
CPE cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
Summary
  • (es) Se identificó una vulnerabilidad de Cross-Site Request Forgery (CSRF) en las versiones de firmware de la serie ioLogik E1200 v3.3 y anteriores. Un atacante puede aprovechar esta vulnerabilidad para engañar a un cliente para que realice una solicitud no intencionada al servidor web, que será tratada como una solicitud auténtica. Esta vulnerabilidad puede llevar a un atacante a realizar operaciones en nombre del usuario víctima.
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - Vendor Advisory
First Time Moxa iologik E1210 Firmware
Moxa iologik E1242
Moxa iologik E1212
Moxa iologik E1211
Moxa iologik E1242 Firmware
Moxa iologik E1213
Moxa iologik E1240
Moxa iologik E1212 Firmware
Moxa iologik E1260
Moxa iologik E1241 Firmware
Moxa iologik E1213 Firmware
Moxa iologik E1262
Moxa iologik E1262 Firmware
Moxa iologik E1211 Firmware
Moxa
Moxa iologik E1240 Firmware
Moxa iologik E1241
Moxa iologik E1214
Moxa iologik E1214 Firmware
Moxa iologik E1260 Firmware
Moxa iologik E1210

23 Dec 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-23 09:15

Updated : 2023-12-28 15:26


NVD link : CVE-2023-5961

Mitre link : CVE-2023-5961

CVE.ORG link : CVE-2023-5961


JSON object : View

Products Affected

moxa

  • iologik_e1260
  • iologik_e1210
  • iologik_e1242
  • iologik_e1241
  • iologik_e1213_firmware
  • iologik_e1240
  • iologik_e1260_firmware
  • iologik_e1241_firmware
  • iologik_e1214_firmware
  • iologik_e1212
  • iologik_e1262
  • iologik_e1212_firmware
  • iologik_e1213
  • iologik_e1214
  • iologik_e1242_firmware
  • iologik_e1262_firmware
  • iologik_e1210_firmware
  • iologik_e1211
  • iologik_e1211_firmware
  • iologik_e1240_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)