← Back to CVE List
Vulnerability Intelligence Report

CVE-2024-45504

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-352 ↗CWE-352 Cross-Site Request Forgery (CSRF)

Affected Products & Versions

Vendor Product Affected Versions
Alps System Integration Co., Ltd. InterSafe WebFilter prior to V9.1SP4 Build1653 (affected)
Alps System Integration Co., Ltd. InterSafe LogDirector versions before the replacement file released on 2024 September 9 (affected)
Alps System Integration Co., Ltd. InterSafe GatewayConnection versions before 2024 July 20 maintenance (affected)
Alps System Integration Co., Ltd. InterSafe LogNavigator prior to Ver.1.1.1 (affected)
Alps System Integration Co., Ltd. InterSafe CATS versions before 2024 July 4 maintenance (affected)
Alps System Integration Co., Ltd. InterSafe MobileSecurity versions before 2024 August 31 maintenance (affected)
Trend Micro Incorporated InterScan WebManager 9.0 (affected), 9.0 Service Pack 1 (affected), 9.1 (affected), 9.1 Service Pack 1 (affected), 9.1 Service Pack 2 (affected), 9.1 Service Pack 3 (affected), and 9.1 Service Pack 4 (affected)
MIROKU JYOHO SERVICE CO., LTD. MJS WebFiltering versions before 2024 July 4 maintenance (affected)
Hammock Corporation AssetView F versions before 2024 July 4 maintenance (affected)
MOTEX Inc. LANSCOPE EndpointManager WebFiltering versions before 2024 July 4 maintenance (affected)
AXSEED,Inc. SPPM BizBrowser versions before 2024 June 18 maintenance (affected)
AXSEED,Inc. SPPM Secure Filtering versions before 2024 July 20 maintenance (affected)
QualitySoft Corporation URL Filtering versions before 2024 July 4 maintenance (affected)
JMA Systems Corporation KAITO SecureBrowser versions before 2024 July 4 maintenance (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.300%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJPCERT/CC · CERT · Japan
Reserved2024-08-30T14:44:59
Published2024-09-10T04:35:19
Last Updated2024-11-04T20:53:34

LINK COPIED TO CLIPBOARD