Lucene search

K
nvd[email protected]NVD:CVE-2024-38501
HistoryAug 13, 2024 - 1:15 p.m.

CVE-2024-38501

2024-08-1313:15:12
CWE-79
web.nvd.nist.gov
4
unauthenticated attacker
remote access
html injection
limited length
low-privileged access

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.

Affected configurations

Nvd
Node
pepperl-fuchsicdm-rx\/tcp_socketserver_firmwareRange<11.65
AND
pepperl-fuchsicdm-rx\/tcp-16db9\/rj45-rmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-16rj45\/2rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-16rj45\/rj45-rmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-2db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/tcp-2st\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/tcp-32rj45\/rj45-rmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/tcp-4db9\/2rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-8db9\/2rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/tcp-db9\/rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/tcp-db9\/rj45-pm2Match-
OR
pepperl-fuchsicdm-rx\/tcp-st\/rj45-dinMatch-
Node
pepperl-fuchsprofinet_firmwareRange<3.4.9
AND
pepperl-fuchsicdm-rx\/pn-2db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn-2st\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn-db9\/rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/pn-st\/rj45-dinMatch-
Node
pepperl-fuchsprofinet\/modbus_firmwareRange<1.0.7
AND
pepperl-fuchsicdm-rx\/pn1-2db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn1-2st\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn1-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn1-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/pn1-db9\/rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/pn1-st\/rj45-dinMatch-
Node
pepperl-fuchsmodbus_router_firmwareRange<7.09
OR
pepperl-fuchsmodbus_server_firmwareRange<7.11
OR
pepperl-fuchsmodbus_tcp_firmwareRange<7.11
AND
pepperl-fuchsicdm-rx\/mod-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/mod-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/mod-st\/rj45-dinMatch-
Node
pepperl-fuchsethernet\/ip_firmwareRange<7.22
AND
pepperl-fuchsicdm-rx\/en-2db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en-2st\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en-db9\/rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/en-st\/rj45-dinMatch-
Node
pepperl-fuchseip\/modbus_firmwareRange<1.08
AND
pepperl-fuchsicdm-rx\/en1-2db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en1-2st\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en1-4db9\/2rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en1-db9\/rj45-dinMatch-
OR
pepperl-fuchsicdm-rx\/en1-db9\/rj45-pmMatch-
OR
pepperl-fuchsicdm-rx\/en1-st\/rj45-dinMatch-
VendorProductVersionCPE
pepperl-fuchsicdm-rx\/tcp_socketserver_firmware*cpe:2.3:o:pepperl-fuchs:icdm-rx\/tcp_socketserver_firmware:*:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-16db9\/rj45-rm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-16db9\/rj45-rm:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-16rj45\/2rj45-pm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-16rj45\/2rj45-pm:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-16rj45\/rj45-rm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-16rj45\/rj45-rm:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-2db9\/rj45-din-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-2db9\/rj45-din:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-2st\/rj45-din-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-2st\/rj45-din:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-32rj45\/rj45-rm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-32rj45\/rj45-rm:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-4db9\/2rj45-din-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-4db9\/2rj45-din:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-4db9\/2rj45-pm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-4db9\/2rj45-pm:-:*:*:*:*:*:*:*
pepperl-fuchsicdm-rx\/tcp-8db9\/2rj45-pm-cpe:2.3:h:pepperl-fuchs:icdm-rx\/tcp-8db9\/2rj45-pm:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 481

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%

Related for NVD:CVE-2024-38501