CVE-2014-2370

Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
omronns_series_system_program_firmware
8.1
omronns_series_system_program_firmware
8.68
omronns10_hmi_terminal
-
omronns12_hmi_terminal
-
omronns15_hmi_terminal
-
omronns5_hmi_terminal
-
omronns8_hmi_terminal
-
𝑥
= Vulnerable software versions