{"api_version":"1","generated_at":"2026-07-23T05:01:49+00:00","cve":"CVE-2017-6038","urls":{"html":"https://cve.report/CVE-2017-6038","api":"https://cve.report/api/cve/CVE-2017-6038.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-6038","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-6038"},"summary":{"title":"CVE-2017-6038","description":"A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-06-30 03:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-352","CWE-352 CWE-352"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.1","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Belden Hirschmann GECKO (Update A) | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-6038","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-6038","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Belden Hirschmann GECKO","version":"affected Belden Hirschmann GECKO","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"6038","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"belden_hirschmann","cpe5":"gecko_lite_managed_switch","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"6038","vulnerable":"1","versionEndIncluding":"2.0.00","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"belden_hirschmann","cpe5":"gecko_lite_managed_switch_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:18:49.614Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Belden Hirschmann GECKO","vendor":"n/a","versions":[{"status":"affected","version":"Belden Hirschmann GECKO"}]}],"datePublic":"2017-06-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-352","description":"CWE-352","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-06-30T02:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-6038","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Belden Hirschmann GECKO","version":{"version_data":[{"version_value":"Belden Hirschmann GECKO"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-352"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-026-02A"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-6038","datePublished":"2017-06-30T02:35:00.000Z","dateReserved":"2017-02-16T00:00:00.000Z","dateUpdated":"2024-08-05T15:18:49.614Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-06-30 03:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-352","CWE-352 CWE-352"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:belden_hirschmann:gecko_lite_managed_switch_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.00","matchCriteriaId":"F6C3FE20-F449-4AE3-A70D-125BE0934473"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:belden_hirschmann:gecko_lite_managed_switch:-:*:*:*:*:*:*:*","matchCriteriaId":"6F981F2D-B30E-49A8-9FFB-5A9A01C6D46C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"6038","Ordinal":"1","Title":"CVE-2017-6038","CVE":"CVE-2017-6038","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"6038","Ordinal":"1","NoteData":"A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.","Type":"Description","Title":"CVE-2017-6038"},{"CveYear":"2017","CveId":"6038","Ordinal":"2","NoteData":"2017-06-29","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"6038","Ordinal":"3","NoteData":"2017-06-29","Type":"Other","Title":"Modified"}]}}}