PT-2023-1305 · Moxa · Moxa Sds-3008 Series Industrial Ethernet Switch

Patrick Desantis

·

Publicado

2023-02-02

·

Atualizado

2023-02-15

·

CVE-2022-41312

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moxa SDS-3008 Series Industrial Ethernet Switch version 2.1
Description A stored cross-site scripting issue exists in the web application functionality, allowing arbitrary Javascript execution through a specially-crafted HTTP request. The vulnerability is related to insufficient protection of the web page structure when handling the switch description field in the Switch Information section. An attacker can exploit this by sending an HTTP request to trigger the issue, potentially leading to the execution of arbitrary JavaScript code. The form field id="Switch Description" and name="switch description" are specifically implicated.
Recommendations For Moxa SDS-3008 Series Industrial Ethernet Switch version 2.1, consider disabling the web application functionality or restricting access to the Switch Information section until a patch is available. As a temporary workaround, avoid using the switch description field in the affected form until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00583
CVE-2022-41312

Produtos afetados

Moxa Sds-3008 Series Industrial Ethernet Switch