Description
The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
Published: 2024-05-06
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below: * NPort 5100A Series: Please contact Moxa Technical Support for the security patch (v1.6.3). https://www.moxa.com/tw/support/technical-support

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32156 The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2024-08-01T20:12:07.894Z

Reserved: 2024-04-10T10:56:14.293Z

Link: CVE-2024-3576

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.894Z

cve-icon NVD

Status : Deferred

Published: 2024-05-06T12:15:08.433

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-3576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses