IPTIME NAS1DUAL CSRF Vulnerability
Vulnerability Description
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23771
Credits & Attribution
No credits recorded in the NVD database.
More from EFM Networks Co., Ltd
View All →Affected Vendor
EFM Networks Co., Ltd
View all reports →