VulnerabilityModified
CVE-2014-3110
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via…
MEDIUM 4.3EPSS 5.34%
Does this matter?
Lower severity and a low EPSS score (5.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 5.34% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- honeywell/falcon xlweb linux controller · honeywell/falcon xlweb xlwebexe
- Source
- cve@mitre.org
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-175-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/68838
- https://www.exploit-db.com/exploits/44749/
- http://ics-cert.us-cert.gov/advisories/ICSA-14-175-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/68838
- https://www.exploit-db.com/exploits/44749/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.