PT-2013-1741 · Trimble · Trimble Infrastructure Gnss Series Receivers Netr3+4

Published

2013-03-07

·

Updated

2023-12-01

·

CVE-2012-5053

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 versions prior to 4.70 Trimble Infrastructure GNSS Series Receivers NetRS versions prior to 1.3-2
Description A cross-site scripting (XSS) issue in the Receiver Web User Interface allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This could potentially lead to unauthorized access or control of the affected systems.
Recommendations For Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 versions prior to 4.70, update to version 4.70 or later. For Trimble Infrastructure GNSS Series Receivers NetRS versions prior to 1.3-2, update to version 1.3-2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2012-5053

Affected Products

Trimble Infrastructure Gnss Series Receivers Netr3
Trimble Infrastructure Gnss Series Receivers Netr5
Trimble Infrastructure Gnss Series Receivers Netr8
Trimble Infrastructure Gnss Series Receivers Netr9
Trimble Infrastructure Gnss Series Receivers Netrs