| |
Vulnerability CVE-2014-2370
Published: 2014-07-24
Description: |
Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data. |
CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
3.5/10 |
2.9/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
http://ics-cert.us-cert.gov/advisories/ICSA-14-203-01
http://www.securityfocus.com/bid/68836
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|