CVE-2021-35956
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
30/06/2021
Last modified:
06/07/2021
Description
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:akcp:sensorprobe2_firmware:*:*:*:*:*:*:*:* | sp480-20210624 (excluding) | |
cpe:2.3:h:akcp:sensorprobe2:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:akcp:sensorprobe4_firmware:*:*:*:*:*:*:*:* | sp480-20210624 (excluding) | |
cpe:2.3:h:akcp:sensorprobe4:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:akcp:sensorprobe8_firmware:*:*:*:*:*:*:*:* | sp480-20210624 (excluding) | |
cpe:2.3:h:akcp:sensorprobe8:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:akcp:sensorprobe8-x20_firmware:*:*:*:*:*:*:*:* | sp480-20210624 (excluding) | |
cpe:2.3:h:akcp:sensorprobe8-x20:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:akcp:sensorprobe8-x60_firmware:*:*:*:*:*:*:*:* | sp480-20210624 (excluding) | |
cpe:2.3:h:akcp:sensorprobe8-x60:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page