CVE-2024-46453: XSS
Published Sep 27, 2024
·Updated
A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
2 affected components
All of the following
Honeywell Iq3xcite Firmware>=2.31<3.11
Honeywell Iq3xcite
Event History
Sep 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46453?
CVE-2024-46453 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How can I fix CVE-2024-46453?
To fix CVE-2024-46453, update your Honeywell iq3xcite firmware to a version later than 3.05.
3
Which versions of iq3xcite are affected by CVE-2024-46453?
CVE-2024-46453 affects iq3xcite firmware versions 2.31 to 3.05.
4
What type of attack does CVE-2024-46453 enable?
CVE-2024-46453 enables attackers to execute arbitrary web scripts or HTML through cross-site scripting.
5
Who is the vendor of the software affected by CVE-2024-46453?
The vendor of the affected software is Honeywell.