Stored XSS Vulnerability in Symmetricom SyncServer Devices
CVE-2020-9028
6.1MEDIUM
What is CVE-2020-9028?
Certain versions of Symmetricom SyncServer devices are vulnerable to a stored XSS attack, which can occur through the 'newUserName' parameter on the User Creation, Deletion, and Password Maintenance screen. An attacker can exploit this vulnerability to inject malicious scripts, potentially compromising the security of the device and permitting unauthorized access.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved