← Back to CVE List

CVE-2020-36283

Published: 2021-03-24T16:15Z
Last Modified: 2024-11-21T05:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt