Reflected XSS Vulnerability in Extreme Management Center from Extreme Networks
CVE-2020-13820

6.1MEDIUM

Key Information:

Vendor
CVE Published:
3 August 2020

What is CVE-2020-13820?

Extreme Management Center version 8.4.1.24 is vulnerable to unauthenticated reflected XSS attacks, which can be triggered through a parameter in a GET request. This allows attackers to potentially execute malicious scripts in the context of users who access the compromised links, leading to unauthorized actions or data exposure. It is crucial for users of this product to assess their exposure and apply necessary security measures to mitigate the risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.