CVE-2023-42765: Westermo Lynx Cross-site Scripting
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42765?
CVE-2023-42765 has a severity rating that depends on the context of its exploitation, typically considered high due to its potential for cross-site scripting attacks.
How do I fix CVE-2023-42765?
To fix CVE-2023-42765, update the Westermo L206-f2g firmware to the latest version where the vulnerability has been addressed.
What type of attack does CVE-2023-42765 facilitate?
CVE-2023-42765 facilitates cross-site scripting (XSS) attacks through the injection of malicious JavaScript code.
Who is affected by CVE-2023-42765?
CVE-2023-42765 affects users of the Westermo L206-f2g firmware version 4.24.
What parameters are involved in the CVE-2023-42765 vulnerability?
The vulnerability in CVE-2023-42765 specifically involves the 'username' parameter in the SNMP configuration.