The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32156 The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
Fixes

Solution

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below: * NPort 5100A Series: Please contact Moxa Technical Support for the security patch (v1.6.3). https://www.moxa.com/tw/support/technical-support


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2024-08-01T20:12:07.894Z

Reserved: 2024-04-10T10:56:14.293Z

Link: CVE-2024-3576

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-06T12:15:08.433

Modified: 2024-11-21T09:29:54.783

Link: CVE-2024-3576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses