CVE-2021-40517
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.04 |
| Running on/with | Platform Versions |
|---|---|
Airangel Hsmx App 25 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.04 |
| Running on/with | Platform Versions |
|---|---|
Airangel Hsmx App 100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.04 |
| Running on/with | Platform Versions |
|---|---|
Airangel Hsmx App 1000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.04 |
| Running on/with | Platform Versions |
|---|---|
Airangel Hsmx App 5000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.04 |
| Running on/with | Platform Versions |
|---|---|
Airangel Hsmx App 20000 | All versions |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.