CVE-2023-38255
Summary
| CVE | CVE-2023-38255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-18 21:15:00 UTC |
| Updated | 2023-11-07 04:17:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Socomec | Modulys Gp | - | All | All | All |
| Operating System | Socomec | Modulys Gp Firmware | 01.12.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Socomec MOD3GP-SY-120K | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.