Secure Computing SnapGear Management Console SG560
cpe:2.3:h:securecomputing:snapgear_sg560:*:*:*:*:*:*:*
- 3.1.5u1
A cross-site request forgery (CSRF) vulnerability has been identified in Secure Computing SnapGear Management Console SG560 version 3.1.5. This vulnerability allows attackers to perform administrative actions without user consent. By crafting a malicious web page that a logged-in user visits, an attacker can automatically submit a form to create a new super user account with full administrative privileges.
Exploitation of this vulnerability allows for unauthorized administrative actions to be performed, including the creation of super user accounts with full privileges.
To reproduce this vulnerability, an attacker must persuade a logged-in user to visit a malicious web page. This page should be crafted to automatically submit a form to the SnapGear Management Console's admin users interface, including the necessary fields to create a new super user account. Once the form is submitted, the new account will be created with administrative rights.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.