CVE-2023-45227: Westermo Lynx Cross-site Scripting
Published Feb 6, 2024
·Updated
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.
Affected Software
2 affected components
All of the following
Westermo L206-f2g Firmware=4.24
Westermo L206-f2g
Event History
Feb 6, 2024
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45227?
CVE-2023-45227 is classified as a high severity vulnerability due to the potential for attacker exploitation.
2
How do I fix CVE-2023-45227?
To fix CVE-2023-45227, update the Westermo L206-f2g firmware to the latest version that mitigates the vulnerability.
3
What software is affected by CVE-2023-45227?
CVE-2023-45227 affects the Westermo L206-f2g firmware version 4.24.
4
What type of attack does CVE-2023-45227 enable?
CVE-2023-45227 enables attackers to execute arbitrary JavaScript through cross-site scripting (XSS) in a vulnerable web application.
5
Who is at risk from CVE-2023-45227?
Organizations using Westermo L206-f2g firmware version 4.24 are at risk of exploitation due to CVE-2023-45227.