VulnerabilityModified
CVE-2021-41871
An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4.
MEDIUM 5.4EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.46% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- socomec/remote view pro firmware
- Source
- cve@mitre.org
References
- https://f20.be/cves/socomecThird Party Advisory
- https://www.socomec.com/remote-view-software_en.htmlVendor Advisory
- https://f20.be/cves/socomecThird Party Advisory
- https://www.socomec.com/remote-view-software_en.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.