Stored Cross-Site Scripting in Moxa SDS-3008 Series Industrial Ethernet Switch
CVE-2022-41313

4.3MEDIUM

Key Information:

Vendor
Moxa
Vendor
CVE Published:
7 February 2023

Summary

The Moxa SDS-3008 Series Industrial Ethernet Switch 2.1 is impacted by a stored cross-site scripting vulnerability that allows for the execution of arbitrary JavaScript. This vulnerability can be exploited through a specially crafted HTTP request, enabling an attacker to manipulate the web application functionality, potentially compromising sensitive information or the integrity of the system. It highlights the importance of maintaining updated firmware and securing web interfaces against such attacks.

Affected Version(s)

SDS-3008 Series Industrial Ethernet Switch 2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.