Cross-site Scripting Vulnerability in RDT400 by SICK
CVE-2023-43698

7.1HIGH

Key Information:

Vendor
Sick Ag
Status
Vendor
CVE Published:
9 October 2023

Summary

A Cross-site Scripting vulnerability exists in the RDT400 product from SICK, enabling an unprivileged remote attacker to inject malicious code. This flaw allows the attacker to execute arbitrary code in the clients' browsers through web page generation that improperly neutralizes user input. Attackers can exploit this vulnerability to manipulate web content and potentially compromise client systems.

Affected Version(s)

APU0200 all versions

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.