CVE-2023-27572: XSS
An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18041520711.NCS.10. A reflected XSS vulnerability was discovered in the httpsredirect.php web page via the page parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27572?
CVE-2023-27572 is a reflected XSS vulnerability in the https_redirect.php web page of CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10 firmware.
How severe is CVE-2023-27572?
CVE-2023-27572 has a severity rating of 6.1 (medium).
How does CVE-2023-27572 impact the affected software?
CVE-2023-27572 can be exploited through the 'page' parameter in the https_redirect.php web page of CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10 firmware, allowing for potential cross-site scripting (XSS) attacks.
Is Commscope Dg3450 firmware version ar01.02.056.18_041520_711.ncs.10 affected by CVE-2023-27572?
Yes, Commscope Dg3450 firmware version ar01.02.056.18_041520_711.ncs.10 is affected by CVE-2023-27572.
How can I fix CVE-2023-27572?
To fix CVE-2023-27572, users should consider updating the firmware of their CommScope Arris DG3450 Cable Gateway to a version that addresses the vulnerability.