CVE-2018-25090
Wago: Improper Neutralization of Input During Web Page Generation in multiple devices
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 mar 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Productos afectados
WAGO · Controller BACnet/IPWAGO · Controller BACnet MS/TPWAGO · Ethernet Controller 3rd GenerationWAGO · Fieldbus Coupler Ethernet 3rd Generation¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →