VULNERABILITY INTELLIGENCE
CVE-2023-34412
CVSS score4.8 MEDIUM
EPSS probability0.43%
CISA KEVNot currently listed
Published2023-08-17
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Description
A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).
Weakness classification
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Primary references
- info@cert.vde.com — Third Party Advisory
- info@cert.vde.com — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory