QID 590537

Date Published: 2021-09-20

QID 590537: Exacq Technologies exacqVision Enterprise Manager Cross-site Scripting Vulnerability (ICSA-21-180-02)

AFFECTED PRODUCTS
The following versions of Exacq TechnologiesexacqVision Enterprise Manager software are affected:
exacqVision Enterprise Manager: Version 20.12 and prior

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability could allow an attacker to send malicious requests on behalf of the victim.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-180-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590537

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-180-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-180-02