PT-2021-4446 · Unknown · Xarrow Scada

Michael Heinzl

+1

·

Published

2021-08-18

·

Updated

2022-05-25

·

CVE-2021-33001

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions xArrow SCADA versions 7.2 and prior
Description The issue is related to a cross-site scripting vulnerability due to the bdate parameter of the xhisvalue.htm resource. This may allow an unauthorized attacker to execute arbitrary code. The vulnerability is associated with a lack of protection for the web page structure, which can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For xArrow SCADA versions 7.2 and prior, consider disabling the xhisvalue.htm resource or restricting access to the bdate parameter until a patch is available. As a temporary workaround, avoid using the bdate parameter in the affected resource to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05076
CVE-2021-33001

Affected Products

Xarrow Scada