Vulnerability Description
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chiyu-T | Bf-430 Firmware | < 1.16.00 |
| Chiyu-T | Bf-430 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156289/CHIYU-BF430-TCP-IP-Converter-Cross-SExploitThird Party AdvisoryVDB Entry
- https://drive.google.com/open?id=1eDN0rsGPs4-yxeMxl7MGh__yjdbl-wONExploitThird Party Advisory
- http://packetstormsecurity.com/files/156289/CHIYU-BF430-TCP-IP-Converter-Cross-SExploitThird Party AdvisoryVDB Entry
- https://drive.google.com/open?id=1eDN0rsGPs4-yxeMxl7MGh__yjdbl-wONExploitThird Party Advisory
FAQ
What is CVE-2020-8839?
CVE-2020-8839 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
How severe is CVE-2020-8839?
CVE-2020-8839 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8839?
Check the references section above for vendor advisories and patch information. Affected products include: Chiyu-T Bf-430 Firmware, Chiyu-T Bf-430.