CVE-2024-31971: XSS
UNSUPPORTED WHEN ASSIGNED Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote attackers to inject arbitrary JavaScript, as demonstrated by /mainPassword.html, /processIdentity.html, /public.html, /dhcp.html, /private.html, /hostname.html, /connectivity.html, /NetworkMonitor.html, /trafficMonitoringConfig.html, and /wizardMain.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31971?
CVE-2024-31971 is classified as a high severity vulnerability due to its potential for remote code execution via stored cross-site scripting.
How do I fix CVE-2024-31971?
To mitigate CVE-2024-31971, users should upgrade to the latest firmware version provided by AdTran that addresses these XSS vulnerabilities.
What devices are affected by CVE-2024-31971?
CVE-2024-31971 specifically affects AdTran NetVanta 3120 devices running firmware version 18.01.01.00.E.
What types of attacks can exploit CVE-2024-31971?
CVE-2024-31971 allows remote attackers to execute arbitrary JavaScript in the context of the user’s session through stored XSS vulnerabilities.
Is there a workaround for CVE-2024-31971?
Currently, the primary recommendation for CVE-2024-31971 is to apply the firmware update as a comprehensive workaround.