CVE-2023-35793
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Sep 27, 2023
Updated: Jan 29, 2024
CWE ID 352
Summary
CVE-2023-35793 is a vulnerability affecting the Cassia Access Controller version 2.1.1.2303271039. This issue permits attackers to execute Cross-Site Request Forgery (CSRF) attacks by exploiting a weakness in the web SSH session establishment process. Successful exploitation could allow attackers to manipulate user actions, potentially leading to unauthorized access or data theft. Organizations using this version of the Cassia Access Controller are advised to apply the necessary patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Cassia Networks Access Controller
Affected Vendors
- Cassia Networks