An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.
No PoCs from references.
- https://github.com/Dodge-MPTC/CVE-2023-35793-CSRF-On-Web-SSH
- https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking
- https://github.com/nomi-sec/PoC-in-GitHub