Lucene search

K
cve[email protected]CVE-2023-6333
HistoryDec 07, 2023 - 6:15 p.m.

CVE-2023-6333

2023-12-0718:15:08
CWE-79
web.nvd.nist.gov
14
cve-2023-6333
controlbyweb relay
stored cross-site scripting vulnerability
web interface
javascript code
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user’s session.

Affected configurations

NVD
Node
controlbywebx-332-24i_firmwareMatch1.06
AND
controlbywebx-332-24iMatch-
Node
controlbywebx-301-i_firmwareMatch1.15
AND
controlbywebx-301-iMatch-
Node
controlbywebx-301-24i_firmwareMatch1.15
AND
controlbywebx-301-24iMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "X-332-24I",
    "vendor": "ControlByWeb",
    "versions": [
      {
        "status": "affected",
        "version": "Firmware 1.06"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "X-301-I",
    "vendor": "ControlByWeb",
    "versions": [
      {
        "status": "affected",
        "version": "Firmware 1.15"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "X-301-24I",
    "vendor": "ControlByWeb",
    "versions": [
      {
        "status": "affected",
        "version": "Firmware 1.15"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for CVE-2023-6333