Janitza UMG Cross-Site Request Forgery Vulnerability (CVE-2015-3967)
Janitza UMG Cross-Site Request Forgery Vulnerability (CVE-2015-3967)
Release date:
Updated on:
Affected Systems:
Janitza UMG 605
Janitza UMG 604
Janitza UMG 511
Janitza UMG 509
Janitza UMG 508
Description:
CVE (CAN) ID: CVE-2015-3967
Janitza UMG is a power quality measurement product.
The Janitza UMG 508,509,511,604,605 device has multiple cross-site Request Forgery vulnerabilities, which allow remote attackers to exploit this vulnerability to hijack the authentication of arbitrary users.
<* Source: Mattijs van Ommeren
Link: https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03
*>
Suggestion:
Vendor patch:
Janitza
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.janitza.com/experimental-downloads.html
This article permanently updates the link address: