4.3
CVSSv2

CVE-2020-14502

Published: 24/02/2022 Updated: 07/03/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation 1734-aentr_point_i\\/o_dual_port_network_adaptor_series_b_firmware

rockwellautomation 1734-aentr_point_i\\/o_dual_port_network_adaptor_series_c_firmware 6.011

rockwellautomation 1734-aentr_point_i\\/o_dual_port_network_adaptor_series_c_firmware 6.012