Unrated severityNVD Advisory· Published Jul 15, 2007· Updated Apr 23, 2026
CVE-2007-3786
CVE-2007-3786
Description
Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer
Affected products
3cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20031001:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20031001:*:*:*:*:*:*:*
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20060921:*:*:*:*:*:*:*
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20070605:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- labs.calyptix.com/CX-2007-05.phpnvdPatchVendor Advisory
- labs.calyptix.com/CX-2007-05.txtnvdPatchVendor Advisory
- osvdb.org/38174nvd
- secunia.com/advisories/26005nvd
- www.eweek.com/article2/0%2C1759%2C2154646%2C00.aspnvd
- www.securityfocus.com/archive/1/473663/100/0/threadednvd
- www.vupen.com/english/advisories/2007/2539nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35372nvd
News mentions
0No linked articles in our index yet.