Stored XSS Vulnerability in Symmetricom SyncServer Devices
CVE-2020-9028

6.1MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
17 February 2020

What is CVE-2020-9028?

Certain versions of Symmetricom SyncServer devices are vulnerable to a stored XSS attack, which can occur through the 'newUserName' parameter on the User Creation, Deletion, and Password Maintenance screen. An attacker can exploit this vulnerability to inject malicious scripts, potentially compromising the security of the device and permitting unauthorized access.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-9028 : Stored XSS Vulnerability in Symmetricom SyncServer Devices