PT-2023-24863 · Helmholz+1 · Rex 200+2
Published
2023-08-17
·
Updated
2023-08-23
·
CVE-2023-34412
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower than 7.3.2
Description
A vulnerability in the affected devices allows an authenticated remote attacker to inject malicious HTML or JavaScript code, enabling them to store an arbitrary JavaScript payload on the diagnosis page of the device. This page is loaded immediately after login, allowing the attacker to read and write browser data and reduce system performance.
Recommendations
For Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower than 7.3.2, update the firmware to version 7.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the diagnosis page of the device until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rex 200
Rex 250
Mbnet/Mbnet.Rokey