CVE-2023-38255
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.
Affected (1)
Products: Socomec: Modulys Gp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.12.10 |
| Running on/with | Platform Versions |
|---|---|
Socomec Modulys Gp | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.