8.8
CVE-2023-36386
- EPSS 0.47%
- Published 11.07.2023 10:15:10
- Last modified 21.11.2024 08:09:38
- Source productcert@siemens.com
- Teams watchlist Login
- Open Login
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. The value is reflected in the response without sanitization while throwing an “invalid params element name” error on the get_elements parameters.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Ruggedcom Rox Mx5000 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Mx5000re Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1400 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1500 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1501 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1510 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1511 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1512 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1524 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx1536 Firmware Version < 2.16.0
Siemens ≫ Ruggedcom Rox Rx5000 Firmware Version < 2.16.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.47% | 0.631 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
productcert@siemens.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.