CVE-2024-4105

A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw (Reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00
Configurations

No configuration.

History

21 Nov 2024, 09:42

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en FAST/TOOLS y CI Server. La función del servidor WEB HMI del producto afectado para procesar solicitudes HTTP tiene un fallo de seguridad (XSS Reflejado) que permite la ejecución de scripts maliciosos. Por lo tanto, si una PC cliente con medidas de seguridad inadecuadas accede a la URL de un producto que contiene una solicitud maliciosa, el script malicioso puede ejecutarse en la PC cliente. Los productos y versiones afectados son los siguientes: FAST/TOOLS (Paquetes: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 a R10.04 CI Server R1.01.00 a R1.03.00
References () https://web-material3.yokogawa.com/1/36059/files/YSAR-24-0001-E.pdf - () https://web-material3.yokogawa.com/1/36059/files/YSAR-24-0001-E.pdf -

26 Jun 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 06:15

Updated : 2024-11-21 09:42


NVD link : CVE-2024-4105

Mitre link : CVE-2024-4105

CVE.ORG link : CVE-2024-4105


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')