SDS-3008 Series firmware version v2.2 and prior are affected by multiple vulnerabilities in the old version of jQuery. These vulnerabilities could put your security at risk in many ways, such as Cross-site Scripting (XSS) attacks and prototype pollution.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
CVE-2015-9251, CVE-2020-11022, CVE-2020-11023 (jQuery)
|
An attacker can remotely insert HTML or JavaScript into the system via a web interface, causing text/javascript to be executed. |
| 2 |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVE-2019-11358 (jQuery)
|
An attacker can inject attributes that are used in other components to execute cross-site scripting (XSS) attacks. |
Vulnerability Scoring Details
|
ID
|
CVSS
|
Vector
|
Unauthenticated Remote Exploit
|
|---|---|---|---|
| CVE-2015-9251 |
6.1 |
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | Yes |
| CVE-2019-11358 | 6.1 | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | Yes |
| CVE-2020-11022 | 6.9 | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N | Yes |
| CVE-2020-11023 | 6.9 | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-248126-sds-3008-series-multiple-vulnerabilities