Secure Computing SnapGear Management Console SG560 Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Secure Computing SnapGear Management Console SG560 version 3.1.5. This vulnerability allows attackers to perform administrative actions without user consent. By crafting a malicious web page that a logged-in user visits, an attacker can automatically submit a form to create a new super user account with full administrative privileges.

Impact

Exploitation of this vulnerability allows for unauthorized administrative actions to be performed, including the creation of super user accounts with full privileges.

Reproduction

To reproduce this vulnerability, an attacker must persuade a logged-in user to visit a malicious web page. This page should be crafted to automatically submit a form to the SnapGear Management Console's admin users interface, including the necessary fields to create a new super user account. Once the form is submitted, the new account will be created with administrative rights.

Added: Jan 6, 2026, 4:51 PM
Updated: Jan 6, 2026, 4:51 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.9
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.