RSS   Vulnerabilities for 'X-320m-i firmware'   RSS

2019-03-21
 
CVE-2018-18882

CWE-79
 

 
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.

 
 
CVE-2018-18881

CWE-254
 

 
A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.

 


Copyright 2024, cxsecurity.com

 

Back to Top