IM
IronMonkey Threat Research

CVE-2024-4105 MEDIUM

Published: 2024-06-26 | Last Modified: 2026-04-15 | Status: Deferred

Description

A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw (Reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00

Additional Descriptions (1)

Se ha encontrado una vulnerabilidad en FAST/TOOLS y CI Server. La función del servidor WEB HMI del producto afectado para procesar solicitudes HTTP tiene un fallo de seguridad (XSS Reflejado) que permite la ejecución de scripts maliciosos. Por lo tanto, si una PC cliente con medidas de seguridad inadecuadas accede a la URL de un producto que contiene una solicitud maliciosa, el script malicioso puede ejecutarse en la PC cliente. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04 CI Server R1.01.00 a R1.03.00

CVSS Metrics

Base Score: 5.8 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: 7168b535-132a-4efe-a076-338f829b2eb9

Type: Secondary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
7168b535-132a-4efe-a076-338f829b2eb9 Secondary
en CWE-79

References

Notification
Message here