MEDIUM · 5.4

CVE-2020-27980

Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged use...

Vulnerability Description

Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
GenexisPlatinum-4410 Firmware1.28
GenexisPlatinum-4410v2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-27980?

CVE-2020-27980 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged use...

How severe is CVE-2020-27980?

CVE-2020-27980 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-27980?

Check the references section above for vendor advisories and patch information. Affected products include: Genexis Platinum-4410 Firmware, Genexis Platinum-4410.