First published: Fri Apr 14 2023(Updated: )
An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Commscope Dg3450 Firmware | =ar01.02.056.18_041520_711.ncs.10 | |
Commscope Dg3450 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27572 is a reflected XSS vulnerability in the https_redirect.php web page of CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10 firmware.
CVE-2023-27572 has a severity rating of 6.1 (medium).
CVE-2023-27572 can be exploited through the 'page' parameter in the https_redirect.php web page of CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10 firmware, allowing for potential cross-site scripting (XSS) attacks.
Yes, Commscope Dg3450 firmware version ar01.02.056.18_041520_711.ncs.10 is affected by CVE-2023-27572.
To fix CVE-2023-27572, users should consider updating the firmware of their CommScope Arris DG3450 Cable Gateway to a version that addresses the vulnerability.