A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an
authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).
References
Link | Resource |
---|---|
https://cert.vde.com/en/advisories/VDE-2023-012/ | Third Party Advisory |
https://cert.vde.com/en/advisories/VDE-2023-029/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
History
29 Feb 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
Summary | (en) A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS). |
23 Aug 2023, 21:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Redlion mbnet Mdh 841 Firmware
Redlion mbnet Mdh 871 Firmware Redlion mbnet.rokey Rkh 235 Firmware Redlion mbnet Mdh 871 Redlion mbnet Mdh 855 Redlion mbnet Mdh 850 Redlion mbnet Mdh 811 Firmware Redlion mbnet Mdh 876 Firmware Redlion mbnet Mdh 831 Firmware Redlion mbnet Mdh 858 Firmware Redlion mbnet Mdh 816 Redlion mbnet Mdh 876 Redlion mbnet.rokey Rkh 259 Redlion mbnet Mdh 850 Firmware Redlion Redlion mbnet.rokey Rkh 216 Redlion mbnet Mdh 816 Firmware Redlion mbnet Mdh 841 Redlion mbnet Mdh 831 Redlion mbnet Mdh 859 Firmware Redlion mbnet Mdh 811 Helmholz rex 250 Helmholz rex 200 Firmware Redlion mbnet Mdh 859 Redlion mbnet.rokey Rkh 210 Helmholz rex 200 Redlion mbnet.rokey Rkh 235 Redlion mbnet Mdh 858 Redlion mbnet.rokey Rkh 216 Firmware Redlion mbnet.rokey Rkh 259 Firmware Redlion mbnet Mdh 835 Redlion mbnet.rokey Rkh 210 Firmware Redlion mbnet Mdh 855 Firmware Helmholz Helmholz rex 250 Firmware Redlion mbnet Mdh 835 Firmware |
|
References | (MISC) https://cert.vde.com/en/advisories/VDE-2023-029/ - Third Party Advisory | |
References | (MISC) https://cert.vde.com/en/advisories/VDE-2023-012/ - Third Party Advisory | |
CPE | cpe:2.3:h:redlion:mbnet.rokey_rkh_210:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_816:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_871:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_811:-:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex_250_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_816_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_841:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_850_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet.rokey_rkh_216:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_831:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_876_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_858_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet.rokey_rkh_235_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex_200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet.rokey_rkh_259:-:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_250:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_831_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_850:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_835_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_835:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet.rokey_rkh_210_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet.rokey_rkh_235:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet.rokey_rkh_216_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet.rokey_rkh_259_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_876:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_871_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_855:-:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_859:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_841_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:redlion:mbnet_mdh_858:-:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_859_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_811_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:redlion:mbnet_mdh_855_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
17 Aug 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-17 14:15
Updated : 2024-02-29 01:39
NVD link : CVE-2023-34412
Mitre link : CVE-2023-34412
CVE.ORG link : CVE-2023-34412
JSON object : View
Products Affected
redlion
- mbnet.rokey_rkh_259_firmware
- mbnet_mdh_871
- mbnet_mdh_850_firmware
- mbnet_mdh_831_firmware
- mbnet_mdh_858
- mbnet_mdh_859_firmware
- mbnet_mdh_841_firmware
- mbnet.rokey_rkh_210_firmware
- mbnet_mdh_855
- mbnet_mdh_859
- mbnet_mdh_835_firmware
- mbnet.rokey_rkh_235
- mbnet_mdh_811
- mbnet_mdh_811_firmware
- mbnet_mdh_858_firmware
- mbnet.rokey_rkh_235_firmware
- mbnet_mdh_841
- mbnet.rokey_rkh_216_firmware
- mbnet_mdh_871_firmware
- mbnet.rokey_rkh_216
- mbnet_mdh_855_firmware
- mbnet_mdh_850
- mbnet.rokey_rkh_259
- mbnet_mdh_876
- mbnet_mdh_816_firmware
- mbnet_mdh_816
- mbnet_mdh_831
- mbnet_mdh_876_firmware
- mbnet.rokey_rkh_210
- mbnet_mdh_835
helmholz
- rex_250
- rex_250_firmware
- rex_200
- rex_200_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')