8.8
CVSSv3

CVE-2016-4845

Published: 24/09/2016 Updated: 19/02/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware prior to 2.04 allows remote malicious users to hijack the authentication of arbitrary users for requests that delete content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iodata hvl-at4.0_firmware 2.03

iodata hvl-at3.0_firmware 2.03

iodata hvl-at4.0a_firmware 2.03

iodata hvl-a4.0_firmware 2.03

iodata hvl-a3.0_firmware 2.03

iodata hvl-at3.0a_firmware 2.03

iodata hvl-at2.0a_firmware 2.03

iodata hvl-a2.0_firmware 2.03

iodata hvl-at2.0_firmware 2.03

iodata hvl-at1.0s_firmware 2.03

Github Repositories

Proof of concept for CSRF vulnerability(CVE-2016-4825) on IO-DATA Recording Hard Disc Drive

cve-2016-4845_csrf Proof of concept for CSRF vulnerability(CVE-2016-4825) on IO-DATA Recording Hard Disc Drive License These codes are released under the MIT License Please see LICENSEtxt