MEDIUM · 6.1

CVE-2023-22971

Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticate...

Vulnerability Description

Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
HughesHx200 Firmware8.3.1.14
HughesHx200-
HughesHx90 Firmware6.11.0.5
HughesHx90-
HughesHx50L Firmware6.10.0.18
HughesHx50L-
HughesHn9460 Firmware8.2.0.48
HughesHn9460-
HughesHn7000S Firmware6.9.0.37
HughesHn7000S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22971?

CVE-2023-22971 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticate...

How severe is CVE-2023-22971?

CVE-2023-22971 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22971?

Check the references section above for vendor advisories and patch information. Affected products include: Hughes Hx200 Firmware, Hughes Hx200, Hughes Hx90 Firmware, Hughes Hx90, Hughes Hx50L Firmware.