CVE-2024-45372

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 3, 2024
CWE ID 352

Summary

CVE-2024-45372 is a cross-site request forgery vulnerability affecting the MZK-DP300N firmware versions 1.04 and earlier. Users who view a malicious page while logging into the device's web management page may unwittingly execute unintended operations, including changing the login password, due to this security flaw. This issue poses a significant risk, particularly in corporate environments, as it can lead to unauthorized access to sensitive information or system configurations. To mitigate this threat, it is recommended that users upgrade to the latest firmware version and practice safe browsing habits.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share