Lucene search

K
cvelistCERTVDECVELIST:CVE-2023-34412
HistoryAug 17, 2023 - 1:07 p.m.

CVE-2023-34412 Stored XXS vulnerability in mbnet, mbnet.rokey, REX 200 and REX 250

2023-08-1713:07:01
CWE-79
CERTVDE
www.cve.org
cve-2023-34412
stored xxs vulnerability
mbnet
mbnet.rokey
rex 200
rex 250
red lion europe
helmholz
firmware 7.3.2
authenticated remote attacker
high privileges

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

5.6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an
authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "mbNET",
    "vendor": "Red Lion Europe",
    "versions": [
      {
        "lessThan": "7.3.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "mbNET.rokey",
    "vendor": "Red Lion Europe",
    "versions": [
      {
        "lessThan": "7.3.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "REX 200",
    "vendor": "Helmholz",
    "versions": [
      {
        "lessThan": "7.3.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "REX 250",
    "vendor": "Helmholz",
    "versions": [
      {
        "lessThan": "7.3.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

5.6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

Related for CVELIST:CVE-2023-34412