685
VMScore

CVE-2019-7273

Published: 01/07/2019 Updated: 13/10/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

optergy proton

optergy enterprise

Exploits

# Title: Optergy 230a - Cross-Site Request Forgery (Add Admin) # Author: LiquidWorm # Date: 2019-11-05 # Vendor: optergycom/ # Product web page: optergycom/products/ # Affected version: <=230a # Advisory: applied-riskcom/resources/ar-2019-008 # Paper: applied-riskcom/resources/i-own-your-building-managemen ...
Optergy Proton/Enterprise BMS versions 203a and below suffer from an add administrator cross site request forgery vulnerability ...