Lucene search

K
cveMitreCVE-2014-5382
HistoryAug 20, 2014 - 2:55 p.m.

CVE-2014-5382

2014-08-2014:55:06
CWE-79
mitre
web.nvd.nist.gov
19
cve-2014-5382
cross-site scripting
xss
schrack technik microcontrol
firmware 1.7.0
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

52.8%

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web script or HTML via the position textbox in the configuration menu or other unspecified vectors.

Affected configurations

Nvd
Node
schracktechnik_microcontrol_firmwareMatch1.7.0\(937\)
AND
schracktechnik_microcontrolMatch-
VendorProductVersionCPE
schracktechnik_microcontrol_firmware1.7.0(937)cpe:2.3:o:schrack:technik_microcontrol_firmware:1.7.0\(937\):*:*:*:*:*:*:*
schracktechnik_microcontrol-cpe:2.3:h:schrack:technik_microcontrol:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

52.8%

Related for CVE-2014-5382