Reflected XSS Vulnerability in MOXA Devices
CVE-2021-39278

6.1MEDIUM

Key Information:

Vendor
Moxa
Vendor
CVE Published:
7 September 2021

Summary

Certain MOXA network devices are vulnerable to reflected Cross-Site Scripting (XSS) attacks through the Config Import menu. This vulnerability can be exploited by an attacker who tricks a user into visiting a specially crafted URL, which could lead to unauthorized access or manipulation of session information. Affected devices include various models across WAC, OnCell, TAP, and WDR series, potentially putting users at risk if proper security measures are not implemented.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.