← Back

CVE-2014-2370

nvd nist
Published: Jul 24, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.

Affected (7)

6 products
Ns Series System Program Firmware
Ns10 Hmi Terminal
Ns12 Hmi Terminal
Ns15 Hmi Terminal
Ns5 Hmi Terminal
Ns8 Hmi Terminal
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Omron
Version 8.1
Version 8.68
All versions
All versions
All versions
All versions
All versions

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.