6.8
CVSSv2

CVE-2010-2025

Published: 26/05/2010 Updated: 27/05/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote malicious users to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change the administrative password, (4) install modified firmware, or (5) change the access level, as demonstrated by a request to goform/_aslvl.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco scientific atlanta webstar dpc2100r2 2.0.2r1256-060303

Exploits

source: wwwsecurityfocuscom/bid/40346/info Cisco DPC2100 (formerly Scientific Atlanta DPC2100) is prone to multiple security-bypass and cross-site request-forgery vulnerabilities Successful exploits may allow attackers to run privileged commands on the affected device, change configuration settings, modify device firmware, cause denial- ...
The Scientific Atlanta DPC2100 Cable Modem suffers from cross site request forgery and insufficient authentication vulnerabilities ...