4
CVE-2014-2370
- EPSS 0.56%
- Veröffentlicht 24.07.2014 14:55:07
- Zuletzt bearbeitet 06.10.2025 18:15:48
- Quelle ics-cert@hq.dhs.gov
- Teams Watchlist Login
- Unerledigt Login
Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Omron ≫ Ns Series System Program Firmware Version8.1
Omron ≫ Ns Series System Program Firmware Version8.68
Omron ≫ Ns10 Hmi Terminal Version-
Omron ≫ Ns12 Hmi Terminal Version-
Omron ≫ Ns15 Hmi Terminal Version-
Omron ≫ Ns5 Hmi Terminal Version-
Omron ≫ Ns8 Hmi Terminal Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.56% | 0.673 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
ics-cert@hq.dhs.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.