CVE-2023-38255
A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) w
A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.
MEDIUM · CVSS 6.5
EPSS 0.00104
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0