Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Arteche · saTECH BCU