Cross Site Scripting Vulnerability in Evertz Microsystems MViP-II Firmware and Related Products
CVE-2024-26367

6.1MEDIUM

Key Information:

Vendor
CVE Published:
14 May 2024

What is CVE-2024-26367?

A Cross Site Scripting vulnerability has been identified in Evertz Microsystems' MViP-II Firmware and related products. This vulnerability allows remote attackers to craft malicious payloads that can be executed through the login parameters of the affected systems, potentially leading to unauthorized access and control over the devices. Users and administrators are urged to assess their systems and ensure they apply mitigations promptly.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.