PT-2024-3324 · Moxa · Nport 5100A Series

Nicolai Grødum

·

Published

2024-05-06

·

Updated

2024-05-07

·

CVE-2024-3576

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions NPort 5100A Series versions prior to 1.6
Description The issue exists due to the failure to protect the web page structure, allowing a remote attacker to escalate privileges. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output, which may allow malicious users to obtain sensitive information and escalate privileges.
Recommendations For versions prior to 1.6, upgrade to version 1.6 or later to protect sensitive data and prevent privilege escalation. As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation. Avoid using user-controllable input in the affected web server until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-03570
CVE-2024-3576

Affected Products

Nport 5100A Series