Vulnerability Description
An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rletech | Fds-Pc Firmware | 2.1 |
| Rletech | Fds-Pc | - |
| Rletech | Fds-Pc-Dp Firmware | 2.1 |
| Rletech | Fds-Pc-Dp | - |
Related Weaknesses (CWE)
References
- http://misteralfa-hack.blogspot.com/2018/02/bacnet-entrando-en-materia.htmlExploitThird Party Advisory
- http://misteralfa-hack.blogspot.com/2018/02/bacnet-entrando-en-materia.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-7278?
CVE-2018-7278 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACn...
How severe is CVE-2018-7278?
CVE-2018-7278 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7278?
Check the references section above for vendor advisories and patch information. Affected products include: Rletech Fds-Pc Firmware, Rletech Fds-Pc, Rletech Fds-Pc-Dp Firmware, Rletech Fds-Pc-Dp.