vendor:
dotDefender Firewall
by:
hyp3rlinx
7.5
CVSS
HIGH
Cross Site Request Forgery - CSRF
CSRF
CWE
Product Name: dotDefender Firewall
Affected Version From: 5.00.12865
Affected Version To: 5.13-13282
Patch Exists: NO
Related CWE:
CPE: a:applicure:dotdefender_firewall:5.00.12865
Platforms Tested: Windows, Linux
dotDefender Firewall CSRF Vulnerability
Dotdefender firewall (WAF) is vulnerable to cross site request forgery, allowing attackers to make HTTP requests via the victim's browser to the dotdefender management server on behalf of the victim. This can result in modifying or disabling various firewall patterns, User-Defined Rule settings, and global event logging.
Mitigation:
No patch available. To mitigate this vulnerability, users are advised to implement additional security measures such as implementing CSRF protection mechanisms and regularly updating their dotDefender firewall software.