CVE-2024-7698
published 2024-09-10CVE-2024-7698: A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
PriorityP429medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
0.38%
30.5th percentile
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | fl_mguard_2102 | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_2105 | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_4102_pci | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_4102_pcie | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_4302 | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_4305 | < 10.4.1 | 10.4.1 |
| phoenix_contact | fl_mguard_centerport_vpn-1000 | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_core_tx | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_core_tx_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_delta_tx_tx | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_delta_tx_tx_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_gt_gt | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_gt_gt_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_pci4000 | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_pci4000_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_pcie4000 | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_pcie4000_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs2000_tx_tx-b | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs2000_tx_tx_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs2005_tx_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs4000_tx_tx | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs4000_tx_tx-m | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs4000_tx_tx-p | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs4000_tx_tx_vpn | < 8.9.3 | 8.9.3 |
| phoenix_contact | fl_mguard_rs4004_tx_dtx | < 8.9.3 | 8.9.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-10
Published