{"api_version":"1","generated_at":"2026-07-23T23:23:44+00:00","cve":"CVE-2017-13994","urls":{"html":"https://cve.report/CVE-2017-13994","api":"https://cve.report/api/cve/CVE-2017-13994.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-13994","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-13994"},"summary":{"title":"CVE-2017-13994","description":"A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2017-10-05 21:29:00","updated_at":"2019-10-09 23:23:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/100847","name":"100847","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"LOYTEC LVIS-3ME ICSA-17-257-01 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-257-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-257-01","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"LOYTEC LVIS-3ME | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-13994","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-13994","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"13994","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"loytec","cpe5":"lvis-3me","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"13994","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"loytec","cpe5":"lvis-3me","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"13994","vulnerable":"1","versionEndIncluding":"6.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"loytec","cpe5":"lvis-3me_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-13994","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"LOYTEC LVIS-3ME","version":{"version_data":[{"version_value":"LOYTEC LVIS-3ME"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-257-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-257-01"},{"name":"100847","refsource":"BID","url":"http://www.securityfocus.com/bid/100847"}]}},"nvd":{"publishedDate":"2017-10-05 21:29:00","lastModifiedDate":"2019-10-09 23:23:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:loytec:lvis-3me_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"6.1.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:loytec:lvis-3me:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"13994","Ordinal":"111419","Title":"CVE-2017-13994","CVE":"CVE-2017-13994","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"13994","Ordinal":"1","NoteData":"A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"13994","Ordinal":"2","NoteData":"2017-10-05","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"13994","Ordinal":"3","NoteData":"2017-10-06","Type":"Other","Title":"Modified"}]}}}