CVE-2021-27658: exacqVision Enterprise Manager CSS
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27658?
The severity of CVE-2021-27658 is medium with a CVSS score of 5.4.
How does CVE-2021-27658 affect exacqVision Enterprise Manager?
CVE-2021-27658 affects exacqVision Enterprise Manager version 20.12.
What is the CWE classification of CVE-2021-27658?
CVE-2021-27658 is classified as CWE-79, which is a Cross-Site Scripting vulnerability.
How can I fix CVE-2021-27658?
To fix CVE-2021-27658, it is recommended to update to a version of exacqVision Enterprise Manager that includes the necessary validation, filtering, and encoding of user input.
Where can I find more information about CVE-2021-27658?
More information about CVE-2021-27658 can be found at the following sources: [1] https://us-cert.cisa.gov/ics/advisories/icsa-21-180-02 [2] https://us-cert.gov/ics/advisories [3] https://www.johnsoncontrols.com/cyber-solutions/security-advisories