Vulnerability Description
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Armorstart St 284Ee Firmware | - |
| Rockwellautomation | Armorstart St 284Ee | - |
| Rockwellautomation | Armorstart St 281E Firmware | - |
| Rockwellautomation | Armorstart St 281E | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139438Vendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139438Vendor Advisory
FAQ
What is CVE-2023-29022?
CVE-2023-29022 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view use...
How severe is CVE-2023-29022?
CVE-2023-29022 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29022?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Armorstart St 284Ee Firmware, Rockwellautomation Armorstart St 284Ee, Rockwellautomation Armorstart St 281E Firmware, Rockwellautomation Armorstart St 281E.