Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7wf-5vvq-hf3f

Опубликовано: 16 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
около 3 лет назад

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

CVSS3: 7.1
fstec
около 3 лет назад

Уязвимость встроенного веб-сервера микропрограммного обеспечения программируемых логических контроллеров Rockwell Automation Micrologix 1100 и 1400, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79