CVE-2023-43698: XSS
Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the website.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-43698?
CVE-2023-43698 is a vulnerability in the RDT400 in SICK APU that allows an unprivileged remote attacker to run arbitrary code in the client's browser via injecting code into the website.
What is the severity of CVE-2023-43698?
The severity of CVE-2023-43698 is high with a CVSS score of 6.1.
How does CVE-2023-43698 affect me?
If you are using SICK APU with firmware version up to and exclusive of 4.0.0.6, you are vulnerable to CVE-2023-43698 and may be at risk of having arbitrary code injected into your browser.
How do I fix CVE-2023-43698?
To fix CVE-2023-43698, you should update the firmware of your SICK APU to a version that is higher than 4.0.0.6.
Where can I find more information about CVE-2023-43698?
You can find more information about CVE-2023-43698 on the official website of SICK at sick.com/psirt.