CVE-2024-45504 - CVE House
Back to Database
Status published Unknown CVE-2024-45504

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45504

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Alps System Integration Co., Ltd.

View all reports →

Affected Software

InterSafe WebFilter, InterSafe LogDirector, InterSafe GatewayConnection, InterSafe LogNavigator, InterSafe CATS, InterSafe MobileSecurity, InterScan WebManager, MJS WebFiltering, AssetView F, LANSCOPE EndpointManager WebFiltering, SPPM BizBrowser, SPPM Secure Filtering, URL Filtering, KAITO SecureBrowser
Vulnerable Versions:
prior to V9.1SP4 Build1653, versions before the replacement file released on 2024 September 9, versions before 2024 July 20 maintenance, prior to Ver.1.1.1, versions before 2024 July 4 maintenance, versions before 2024 August 31 maintenance, 9.0, 9.0 Service Pack 1, 9.1, 9.1 Service Pack 1, 9.1 Service Pack 2, 9.1 Service Pack 3, and 9.1 Service Pack 4, versions before 2024 June 18 maintenance

Timeline

Official Publish: September 10th, 2024
Last Modified: November 4th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.