4.8
CVSSv3

CVE-2021-34582

Published: 10/11/2021 Updated: 28/07/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact fl_mguard_1102_firmware 1.4.1

phoenixcontact fl_mguard_1102_firmware 1.5.0

phoenixcontact fl_mguard_1102_firmware 1.4.0

phoenixcontact fl_mguard_1105_firmware 1.4.0

phoenixcontact fl_mguard_1105_firmware 1.4.1

phoenixcontact fl_mguard_1105_firmware 1.5.0