Unauthenticated Remote Attackers Can Exploit XSS Vulnerability in Web Page Generation, Leading to Limited Impact on Confidentiality and Integrity
CVE-2018-25090

5.4MEDIUM

Key Information:

Summary

This vulnerability presents an XSS (Cross-Site Scripting) risk, allowing unauthenticated remote attackers to exploit improper input neutralization during web page generation. While user interaction is necessary for the attack to succeed, the security implications include potential unauthorized access to sensitive information and modifications to the integrity of web content. Affected web applications may present a security risk, and developers should ensure input validation mechanisms are implemented to mitigate such vulnerabilities.

Affected Version(s)

Controller BACnet MS/TP 0

Controller BACnet/IP 0

Ethernet Controller 3rd Generation 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.