CVE-2024-38501: Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows HTML injection
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38501?
CVE-2024-38501 is classified as a low severity vulnerability due to its ability to provide only low-privileged access.
How do I fix CVE-2024-38501?
To fix CVE-2024-38501, update the affected Pepperl+Fuchs firmware to a version that mitigates this HTML injection vulnerability.
Which devices are affected by CVE-2024-38501?
CVE-2024-38501 affects various versions of Pepperl+Fuchs ICDM-RX TCP Socketserver firmware up to version 11.65 and Profinet firmware up to version 3.4.9.
Can CVE-2024-38501 be exploited remotely?
Yes, CVE-2024-38501 can be exploited by an unauthenticated remote attacker through a crafted HTML injection.
What impact does CVE-2024-38501 have on my network security?
CVE-2024-38501 can lead to unauthorized low-privileged access, posing risks to the security integrity of affected devices.