Vulnerability Details CVE-2020-36908
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative privileges when a logged-in user visits the page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2020-36908
-
cpe:2.3:h:securecomputing:snapgear_sg560:-
-
cpe:2.3:o:securecomputing:snapgear_sg560_firmware:3.1.5