PT-2024-37715 · Hms Industrial Networks · Anybus-Compactcom

Published

2024-07-11

·

Updated

2024-08-13

·

CVE-2024-6558

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Anybus-CompactCom 30 products (affected versions not specified)
Description The issue is caused by the lack of input sanitation checks, allowing for a XSS attack. This enables the insertion of HTML code into input fields, which is then stored and executed by the host browser when the page is loaded, facilitating social engineering attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6558

Affected Products

Anybus-Compactcom