CVE-2024-38502

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CERTVDECNA
7.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
pepperl-fuchsicdm-rx\/tcp_socketserver_firmware
𝑥
< 11.65
pepperl-fuchsprofinet_firmware
𝑥
< 3.4.9
pepperl-fuchsprofinet\/modbus_firmware
𝑥
< 1.0.7
pepperl-fuchsmodbus_router_firmware
𝑥
< 7.09
pepperl-fuchsmodbus_server_firmware
𝑥
< 7.11
pepperl-fuchsmodbus_tcp_firmware
𝑥
< 7.11
pepperl-fuchsethernet\/ip_firmware
𝑥
< 7.22
pepperl-fuchseip\/modbus_firmware
𝑥
< 1.08
𝑥
= Vulnerable software versions