Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34058 | Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface. |
| Link | Providers |
|---|---|
| https://jpn.nec.com/security-info/secinfo/nv24-009_en.html |
|
Wed, 23 Jul 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 23 Jul 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 29 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NEC
Published:
Updated: 2025-07-24T14:37:20.170Z
Reserved: 2024-11-08T02:59:57.594Z
Link: CVE-2024-11014
Updated: 2024-11-29T13:33:14.208Z
Status : Deferred
Published: 2024-11-29T08:15:04.140
Modified: 2026-06-17T06:56:53.197
Link: CVE-2024-11014
No data.
OpenCVE Enrichment
No data.
EUVD