CVE-2023-6028: SDM Web interface vulnerable to XSS
Published Feb 5, 2024
·Updated
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
Affected Software
1 affected component
Br-automation Automation Runtime<i4.93
Remediation
Information
An update is available that resolves a vulnerability in the product versions listed above.
Event History
Feb 5, 2024
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6028?
CVE-2023-6028 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2023-6028?
To fix CVE-2023-6028, update B&R Automation Runtime to version G4.94 or later.
3
Who is affected by CVE-2023-6028?
CVE-2023-6028 affects users of B&R Automation Runtime versions up to G4.93.
4
What type of attack does CVE-2023-6028 allow?
CVE-2023-6028 allows remote attackers to execute arbitrary JavaScript code in the context of the attacked user's browser session.
5
What software is impacted by CVE-2023-6028?
CVE-2023-6028 impacts the System Diagnostics Manager within B&R Automation Runtime software.