CVE-2024-3576
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: psirt@moxa.com (Secondary)
Description
The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
References (2)
Source: psirt@moxa.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.