A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
Se ha encontrado una vulnerabilidad en FAST/TOOLS proporcionado por Yokogawa Electric Corporation. Este producto no codifica correctamente las URL. Un atacante podría manipular páginas web o ejecutar scripts maliciosos. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Attack Requirements | NONE |
| Privileges Required | NONE |
| User Interaction | ACTIVE |
| Vulnerability Confidentiality | LOW |
| Vulnerability Integrity | NONE |
| Vulnerability Availability | NONE |
| Subsequent Confidentiality | LOW |
| Subsequent Integrity | NONE |
| Subsequent Availability | NONE |
Source: 7168b535-132a-4efe-a076-338f829b2eb9
Type: Secondary
| Source | Type | Description |
|---|---|---|
| 7168b535-132a-4efe-a076-338f829b2eb9 | Secondary |
en
CWE-86
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| yokogawa | fast\/tools | * | <built-in method update of dict object at 0x7e6110a55200> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:yokogawa:fast\/tools:*:*:*:*:*:*:*:* |