← back
CVE-2023-4523

Real Time Automation 460 Series Cross-site Scripting

CVSS 9.4 CRITICALEPSS 0.3%CWE-79
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.4EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Sep 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page, which is index.htm.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →