CVE-2024-5676 describes a Cross-Site Request Forgery (CSRF) vulnerability in the Paradox IP150 Internet Module, specifically version 1.40.00. This medium-severity flaw (CVSS 6.8) arises from the module's lack of CSRF countermeasures and its use of GET requests for state-changing operations, allowing an attacker to trick a logged-in user into executing unintended actions. While the attack complexity is high, successful exploitation could lead to significant integrity and availability impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Paradox Security Systems (Bahamas) Ltd. | IP150 Internet Module | 1.40.00CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.