PT-2024-10614 · Wago · Controller Bacnet Ms/Tp+3

Connor Ford

·

Published

2024-03-13

·

Updated

2024-03-13

·

CVE-2018-25090

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue is related to an unauthenticated remote attacker being able to use an XSS attack due to improper neutralization of input during web page generation. This requires user interaction and leads to a limited impact on confidentiality and integrity, but no impact on availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-25090

Affected Products

Controller Bacnet Ms/Tp
Controller Bacnet/Ip
Ethernet Controller 3Rd Generation
Fieldbus Coupler Ethernet 3Rd Generation