CVE-2014-2370
Summary
| CVE | CVE-2014-2370 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-24 14:55:00 UTC |
| Updated | 2015-10-08 14:59:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Omron | Ns10 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns10 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns12 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns12 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns15 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns15 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns5 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns5 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns8 Hmi Terminal | - | All | All | All |
| Hardware | Omron | Ns8 Hmi Terminal | - | All | All | All |
| Operating System | Omron | Ns Series System Program Firmware | 8.1 | All | All | All |
| Operating System | Omron | Ns Series System Program Firmware | 8.68 | All | All | All |
| Operating System | Omron | Ns Series System Program Firmware | 8.1 | All | All | All |
| Operating System | Omron | Ns Series System Program Firmware | 8.68 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | |
| Omron NS Series HMI Vulnerabilities | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590466 Omron NS Series HMI Multiple Vulnerabilities (ICSA-14-203-01)