CVE-2017-16723
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.
Published
2017-12-11T16:29:00.283
Last Modified
2025-04-20T01:37:25.860
Status
Deferred
Source
[email protected]
Severity
CVSSv3.0: 6.1 (MEDIUM)
CVSSv2 Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
- Access Vector: NETWORK
- Access Complexity: MEDIUM
- Authentication: NONE
- Confidentiality Impact: NONE
- Integrity Impact: PARTIAL
- Availability Impact: NONE
Exploitability Score
8.6
Impact Score
2.9
Weaknesses
Affected Vendors & Products
References
-
http://www.securityfocus.com/bid/102111
Third Party Advisory, VDB Entry
([email protected])
-
https://cert.vde.com/de-de/advisories/vde-2017-004
Issue Tracking, Third Party Advisory
([email protected])
-
https://ics-cert.us-cert.gov/advisories/ICSA-17-341-03
Issue Tracking, Mitigation, Third Party Advisory, US Government Resource
([email protected])
-
http://www.securityfocus.com/bid/102111
Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
https://cert.vde.com/de-de/advisories/vde-2017-004
Issue Tracking, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://ics-cert.us-cert.gov/advisories/ICSA-17-341-03
Issue Tracking, Mitigation, Third Party Advisory, US Government Resource
(af854a3a-2127-422b-91ae-364da2661108)