CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-5676: Paradox IP150 Internet Module Cross-Site Request Forgery

6.8 CVSS

Description

The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.

Classification

CVE ID: CVE-2024-5676

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.8

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H

Affected Products

Vendor: Paradox Security Systems (Bahamas) Ltd.

Product: IP150 Internet Module

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.39% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240321-01_Paradox_Cross_Site_Request_Forgery
https://www.paradox.com/Products/default.asp?CATID=3&SUBCATID=38&PRD=563
http://seclists.org/fulldisclosure/2024/Jun/8

Timeline