CVE-2020-16246
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the victim client.
Affected (2)
Products: Ge: S2020 Firmware, S2024 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 07a06 |
| Running on/with | Platform Versions |
|---|---|
Ge S2020 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 07a06 |
| Running on/with | Platform Versions |
|---|---|
Ge S2024 | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.