Vulnerability Note VU#584363
Zenprise Device Manager CSRF vulnerability
Overview
The Zenprise Device Manager software is susceptible to a cross-site request forgery (CSRF) vulnerability that may result in the compromise of the fleet of mobile devices managed by the product.
Description
Zenprise Device Manager is a mobile device management (MDM) software package that can be used to manage an enterprise's mobile device fleet. The Zenprise Device manager web interface is vulnerable to cross-site request forgery (CSRF) attacks. A successful CSRF attack against an admin user will allow a remote attacker to run commands as the admin user on any device managed by Zenprise Device Manager. |
Impact
By tricking a logged in admin user to visit a specially crafted URL, a remote attacker may be able to access any managed device as the admin. The attacker can then perform any action an admin can, including remotely wiping the device. |
Solution
Apply an update Zenprise has released a patch to address this issue. Current customers can find more information about this vulnerability and patch on the Zenprise customer center. |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Zenprise | Affected | 01 Nov 2011 | 14 Nov 2011 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.zenprise.com/products/zenprise_device_manager/
- http://www.zenpriseportal.com/patches/ZP_SecPatch_618_9995.zip
- http://cwe.mitre.org/data/definitions/352.html
Credit
Thanks to Laurent Oudot of TEHTRI-Security for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: Unknown
- Date Public: 18 Nov 2011
- Date First Published: 18 Nov 2011
- Date Last Updated: 03 Aug 2012
- Severity Metric: 0.89
- Document Revision: 18
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.