Cross-Site Scripting Vulnerability in Technicolor DPC3928SL Devices
CVE-2018-20379

4.7MEDIUM

Key Information:

Vendor
CVE Published:
23 December 2018

What is CVE-2018-20379?

The Technicolor DPC3928SL devices are vulnerable to Cross-Site Scripting (XSS) via a Cross Protocol Injection attack. Attackers can exploit this vulnerability through the setSSID parameter, allowing for potential malicious actions against users. Security measures should be implemented to mitigate this risk and ensure that affected devices are updated to secure versions.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.