Arbitrary Script Execution Vulnerability in Energy Management Controller
CVE-2024-23786

9.3CRITICAL

Key Information:

Vendor
CVE Published:
14 February 2024

Summary

A cross-site scripting vulnerability exists in the Sharp Energy Management Controller with Cloud Services models JH-RVB1 and JH-RV11 for versions Ver.B0.1.9.1 and earlier. This vulnerability allows an attacker with network access to execute arbitrary scripts in the web browsers of users accessing the management interface of the affected products. Exploitation of this flaw may lead to unauthorized actions being performed on behalf of the affected users, potentially compromising sensitive information and overall system integrity.

Affected Version(s)

Energy Management Controller with Cloud Services JH-RVB1 Ver.B0.1.9.1 and earlier

Energy Management Controller with Cloud Services JH-RV11 Ver.B0.1.9.1 and earlier

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.