Unrated severityNVD Advisory· Published Jul 15, 2007· Updated Jun 16, 2026
CVE-2007-3786
CVE-2007-3786
Description
Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20031001:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20031001:*:*:*:*:*:*:*
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20060921:*:*:*:*:*:*:*
- cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20070605:*:*:*:*:*:*:*
- (no CPE)range: < 3.1.20070615
Patches
Vulnerability mechanics
References
8- labs.calyptix.com/CX-2007-05.phpnvdPatchVendor Advisory
- labs.calyptix.com/CX-2007-05.txtnvdPatchVendor Advisory
- osvdb.org/38174nvd
- secunia.com/advisories/26005nvd
- www.eweek.com/article2/0%2C1759%2C2154646%2C00.aspnvd
- www.securityfocus.com/archive/1/473663/100/0/threadednvd
- www.vupen.com/english/advisories/2007/2539nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35372nvd
News mentions
0No linked articles in our index yet.