THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-3141

Clavister E10/E80 Misc Settings Page MiscSettings cross site scripting

AssignerVulDB
Reserved2024-04-01
Published2024-04-01
Updated2024-07-16

Description

EN DE

A vulnerability has been found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This vulnerability affects unknown code of the file /?Page=Node&OBJ=/System/AdvancedSettings/DeviceSettings/MiscSettings of the component Misc Settings Page. The manipulation of the argument WatchdogTimerTime/BufFloodRebootTime/MaxPipeUsers/AVCache Lifetime/HTTPipeliningMaxReq/Reassembly MaxConnections/Reassembly MaxProcessingMem/ScrSaveTime leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258916.

In Clavister E10 and E80 bis 14.00.10 wurde eine problematische Schwachstelle gefunden. Das betrifft eine unbekannte Funktionalität der Datei /?Page=Node&OBJ=/System/AdvancedSettings/DeviceSettings/MiscSettings der Komponente Misc Settings Page. Durch das Beeinflussen des Arguments WatchdogTimerTime/BufFloodRebootTime/MaxPipeUsers/AVCache Lifetime/HTTPipeliningMaxReq/Reassembly MaxConnections/Reassembly MaxProcessingMem/ScrSaveTime mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung. Ein Aktualisieren auf die Version 14.00.11 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.



LOW: 2.4CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
LOW: 2.4CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
3.3CVSS:2.0/AV:N/AC:L/Au:M/C:N/I:P/A:N

Problem types

CWE-79 Cross Site Scripting

Product status

14.00.0
affected

14.00.1
affected

14.00.2
affected

14.00.3
affected

14.00.4
affected

14.00.5
affected

14.00.6
affected

14.00.7
affected

14.00.8
affected

14.00.9
affected

14.00.10
affected

14.00.0
affected

14.00.1
affected

14.00.2
affected

14.00.3
affected

14.00.4
affected

14.00.5
affected

14.00.6
affected

14.00.7
affected

14.00.8
affected

14.00.9
affected

14.00.10
affected

Timeline

2023-10-16:Countermeasure disclosed
2024-04-01:Advisory disclosed
2024-04-01:VulDB entry created
2024-04-04:VulDB entry last update

Credits

Strik3r (VulDB User) reporter

References

https://vuldb.com/?id.258916 (VDB-258916 | Clavister E10/E80 Misc Settings Page MiscSettings cross site scripting) vdb-entry technical-description

https://vuldb.com/?ctiid.258916 (VDB-258916 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

https://vuldb.com/?submit.303451 (Submit #303451 | Clavister Clavister E80 - EagleSeries . Cross-Site Scripting) third-party-advisory

https://github.com/strik3r0x1/Vulns/blob/main/Clavister_E80-RXSS.md exploit

https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260 related

https://my.clavister.com/downloads/?sid=1 patch

cve.org CVE-2024-3141

nvd.nist.gov CVE-2024-3141

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-3141
© Copyright 2024 THREATINT. Made in Cyprus with +