PT-2021-4445 · Unknown · Xarrow Scada

Michael Heinzl

+1

·

Published

2021-08-18

·

Updated

2022-05-25

·

CVE-2021-33021

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions xArrow SCADA versions 7.2 and prior
Description The issue is related to a cross-site scripting vulnerability due to the edate parameter of the xhisalarm.htm resource. This may allow an unauthorized attacker to execute arbitrary code. The vulnerability is associated with a lack of protection for the web page structure, which can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For xArrow SCADA versions 7.2 and prior, consider disabling the xhisalarm.htm resource or restricting access to the edate parameter until a patch is available. As a temporary workaround, avoid using the edate parameter in the affected resource to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05075
CVE-2021-33021

Affected Products

Xarrow Scada