CVE-2021-27465

EUVD-2021-14219
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
emersonx-stream_enhanced_xegp_firmware
*
emersonx-stream_enhanced_xegk_firmware
*
emersonx-stream_enhanced_xefd_firmware
*
emersonx-stream_enhanced_xexf_firmware
*
𝑥
= Vulnerable software versions