CVE-2023-24464: XSS
Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of the stored-cross-site scripting vulnerability in Buffalo network devices?
The vulnerability ID is CVE-2023-24464.
What is the severity of CVE-2023-24464?
The severity of CVE-2023-24464 is medium.
What is the affected software of CVE-2023-24464?
The affected software of CVE-2023-24464 is Buffalo BS-GS2008 firmware Ver. 1.0.10.01.
How can an attacker exploit CVE-2023-24464?
An attacker with access to the web management console of the affected Buffalo network devices can exploit CVE-2023-24464 to execute arbitrary JavaScript on a legitimate user's web browser.
How can I fix CVE-2023-24464?
To fix CVE-2023-24464, update the Buffalo BS-GS2008 firmware to version 1.0.10.01 or later.