MEDIUM🇵🇱 Wersja polska

CVE-2023-38255

CVSS 6.5v3.1pub. 2023-09-18upd. 2024-11-21

A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Socomec Modulys Gp

    HW
    Socomec
    all versions
  • Socomec Modulys Gp Firmware

    OS
    Socomec
    01.12.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2023-41084CRITICAL10.0PL ✓same product

Błędne zarządzanie sesją w Socomec Modulys GP umożliwia kradzież cookie

CVE-2023-39446HIGH8.9same product

Thanks to the weaknesses that the web application has at the user management level, an attacker could o...

CVE-2023-39452HIGH7.5same product

The web application that owns the device clearly stores the credentials within the user managem...

CVE-2023-40221HIGH8.8same product

The absence of filters when loading some sections in the web application of the vulnerable device...

CVE-2023-41965HIGH7.5same product

Sending some requests in the web application of the vulnerable device allows information to be obtained due to...