PT-2022-19193 · Scheduler+2 · Scheduler+3
Takayuki Sasaki
·
Published
2022-05-18
·
Updated
2022-06-02
·
CVE-2022-28717
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rebooter(WATCH BOOT nino RPC-M2C) versions 1.00A through 1.00D
Rebooter(WATCH BOOT light RPC-M5C) all firmware versions
Rebooter(WATCH BOOT L-zero RPC-M4L) all firmware versions
Rebooter(WATCH BOOT mini RPC-M4H) all firmware versions
Rebooter(WATCH BOOT nino RPC-M2CS) versions 1.00A through 1.00D
Rebooter(WATCH BOOT light RPC-M5CS) versions 1.00A through 1.00D
Rebooter(WATCH BOOT L-zero RPC-M4LS) versions 1.00A through 1.20A
Rebooter(Signage Rebooter RPC-M4HSi) version 1.00A
PoE Rebooter(PoE BOOT nino PoE8M2) versions 1.00A through 1.20A
Scheduler(TIME BOOT mini RSC-MT4H) all firmware versions
Scheduler(TIME BOOT RSC-MT8F) all firmware versions
Scheduler(TIME BOOT RSC-MT8FP) all firmware versions
Scheduler(TIME BOOT mini RSC-MT4HS) versions 1.00A through 1.10A
Scheduler(TIME BOOT RSC-MT8FS) versions 1.00A through 1.00E
Contact Converter(POSE SE10-8A7B1) versions 1.00A through 1.20A
Description
A cross-site scripting issue allows a remote attacker with administrative privileges to inject an arbitrary script via unspecified vectors.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Converter
Poe Rebooter
Rebooter
Scheduler