CVE-2023-38255
Published on: Not Yet Published
Last Modified on: 09/22/2023 02:32:00 PM UTC
Certain versions of Modulys Gp from Socomec contain the following vulnerability:
** UNSUPPPORTED WHEN ASSIGNED ** A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.
- CVE-2023-38255 has been assigned by
ics-[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Socomec - MODULYS GP (MOD3GP-SY-120K) version = v01.12.10
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Socomec MOD3GP-SY-120K | CISA | www.cisa.gov text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Socomec | Modulys Gp | - | All | All | All |
Operating System | Socomec | Modulys Gp Firmware | 01.12.10 | All | All | All |
- cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:socomec:modulys_gp_firmware:01.12.10:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE