IM
IronMonkey Threat Research

CVE-2023-1841 HIGH

Published: 2024-02-29 | Last Modified: 2025-03-04 | Status: Analyzed

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue affects MPA2 Access Panel all version prior to R1.00.08.05.  Honeywell released firmware update package MPA2 firmware R1.00.08.05 which addresses this vulnerability. This version and all later versions correct the reported vulnerability.

Additional Descriptions (1)

La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site Scripting') en Honeywell MPA2 Access Panel (módulos de servidor web) permite que XSS utilice caracteres no válidos. Este problema afecta a MPA2 Access Panel en todas las versiones anteriores a R1.00.08.05. Honeywell lanzó el paquete de actualización de firmware MPA2 R1.00.08.05 que soluciona esta vulnerabilidad. Esta versión y todas las versiones posteriores corrigen la vulnerabilidad informada.

CVSS Metrics

Base Score: 4.8 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 1.7

Impact Score: 2.7

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-79
[email protected] Primary
en CWE-79

Affected Products

Vendor Product Version Update Type
honeywell mpa2_firmware * <built-in method update of dict object at 0x7c3c40dd5a40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:honeywell:mpa2_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:honeywell:mpa2:*:*:*:*:*:*:*:*
Notification
Message here