CVE-2020-9028: XSS
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
CVE-2020-9028
What is the severity level of CVE-2020-9028?
The severity level of CVE-2020-9028 is medium with a CVSS score of 6.1
Which devices are affected by CVE-2020-9028?
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices are affected.
How does the vulnerability in CVE-2020-9028 occur?
The vulnerability in CVE-2020-9028 occurs due to stored XSS via the newUserName parameter on the 'User Creation, Deletion and Password Maintenance' screen when creating a new user.
Is there a fix available for CVE-2020-9028?
There is no available fix mentioned for CVE-2020-9028. It is recommended to follow the advice provided by the vendor or consider applying any patches or mitigation measures suggested.