saTECH BCU Cross-Site Request Forgery Vulnerability
Vulnerability
A cross-site request forgery (CSRF) vulnerability exists in the web application of saTECH BCU firmware version 2.1.3. This vulnerability allows an unauthenticated local attacker to exploit active administrator sessions and perform malicious actions. The specific actions that can be executed depend on the privileges of the logged-in user and may include rebooting the device or altering roles and permissions.
Impact
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of an administrator, potentially allowing for changes to device settings, roles, and permissions, or causing the device to reboot.
Remediation
Users can upgrade to saTECH BCU firmware version 2.2.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
