The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
The identified vulnerability type and potential impact are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) |
An attacker can use this vulnerability to get sensitive information and escalate privileges. |
Vulnerability Scoring Detail
|
ID
|
CVSS
|
Vector
|
Remote Exploit without Auth?
|
|---|---|---|---|
| CVE-2024-3576 |
8.3 |
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-246328-nport-5100a-series-store-xss-vulnerability