HTTP: C2Box Cross Site Request Forgery

This signature detects attempts to exploit a known vulnerability against C2Box. A successful attack can lead to Cross Site Request Forgery.

Extended Description

Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors.

Affected Products

Boxautomation c2box

References

BugTraq: 75569

CVE: CVE-2015-4460

Short Name
HTTP:C2-BOX-CSRF
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
C2Box CVE-2015-4460 Cross Forgery Request Site bid:75569
Release Date
09/19/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Boxautomation

CVSS Score

6.8

Found a potential security threat?